StackRadar

CVE-2026-39395

Medium

Advisory

Published 8 Apr 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
4.3
base score, highest
EPSS
0.002
15th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
16
of 17,781 indexed, latest versions
Container images
18
deployed by those charts
Fix available
3 of 3
affected packages

Cosign's verify-blob-attestation reports false positive when payload parsing fails

Carried by container images the latest versions of 16 of 17,781 indexed charts deploy, on 18 images.

Affected packageAffected versionsFixed inImages
github.com/sigstore/cosigngolangv1.8.0, v1.13.1, v1.13.62.6.36
github.com/sigstore/cosign/v2golangv2.1.1, v2.2.0, v2.2.4, v2.4.1+2 more2.6.311
github.com/sigstore/cosign/v3golangv3.0.43.0.61
OSV records
GHSA-w6c6-c85g-mmv6GO-2026-5694
Also known as
BIT-cosign-2026-39395

Charts affected

16 by stars
ChartLatestAffected imagesRadar Score
harborharborOfficialVerified publisher1.19.21 of 8See more

harbor harbor 1.19.2

1 of the 8 container images this version deploys carry CVE-2026-39395.

Container imageDigestPackageFixed in
goharbor/trivy-adapter-photon:v2.15.2215c07b71c37
github.com/sigstore/cosign/v2@v2.6.2
2.6.3

Open the chart page →

1,650
artifact-hubartifact-hubVerified publisher1.23.02 of 7See more

artifact-hub artifact-hub 1.23.0

2 of the 7 container images this version deploys carry CVE-2026-39395.

Container imageDigestPackageFixed in
aquasec/trivy:0.69.3bcc376de8d77
github.com/sigstore/cosign/v2@v2.6.2
2.6.3
artifacthub/scanner:v1.23.02d8365601f0e
github.com/sigstore/cosign/v2@v2.6.2
2.6.3

Open the chart page →

10,755
policy-controllersigstoreVerified publisher0.10.71 of 2See more

policy-controller sigstore 0.10.7

1 of the 2 container images this version deploys carry CVE-2026-39395.

Container imageDigestPackageFixed in
ghcr.io/sigstore/policy-controller/policy-controllerdigest-pinned0bcd60beb93f
github.com/sigstore/cosign/v2@v2.5.0
2.6.3

Open the chart page →

911
dockyarddockyardVerified publisher0.4.01 of 1See more

dockyard dockyard 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-39395.

Container imageDigestPackageFixed in
ghcr.io/kgma74/dockyard:0.4.0b40439329191
github.com/sigstore/cosign/v2@v2.2.4
2.6.3

Open the chart page →

1,542
kubeservice-cosign-webhookkubservice-chartsVerified publisher1.1.11 of 5See more

kubeservice-cosign-webhook kubservice-charts 1.1.1

1 of the 5 container images this version deploys carry CVE-2026-39395.

Container imageDigestPackageFixed in
dongjiang1989/cosign-webhook:v1.1.02a3ead6a55dc
github.com/sigstore/cosign/v2@v2.1.1
2.6.3

Open the chart page →

7,087
spirephilips-labsVerified publisher0.12.21 of 6See more

spire philips-labs 0.12.2

1 of the 6 container images this version deploys carry CVE-2026-39395.

Container imageDigestPackageFixed in
ghcr.io/spiffe/spire-agent:1.6.062517726d0c4
github.com/sigstore/cosign@v1.13.1
2.6.3

Open the chart page →

7,236
prowlerprowler-appVerified publisher0.0.91 of 5See more

prowler prowler-app 0.0.9

1 of the 5 container images this version deploys carry CVE-2026-39395.

Container imageDigestPackageFixed in
prowlercloud/prowler-api:5.31.14f252d579be2
github.com/sigstore/cosign/v2@v2.6.2
2.6.3

Open the chart page →

8,158
artifact-hubsoftonic1.19.03 of 8See more

artifact-hub softonic 1.19.0

3 of the 8 container images this version deploys carry CVE-2026-39395.

Container imageDigestPackageFixed in
artifacthub/hub:v1.19.0111918d8c399
github.com/sigstore/cosign@v1.13.6
2.6.3
artifacthub/scanner:v1.19.0323d026e78c3
github.com/sigstore/cosign@v1.13.6
2.6.3
artifacthub/tracker:v1.19.06596c8c4d955
github.com/sigstore/cosign@v1.13.6
2.6.3

Open the chart page →

14,491
kyvernodevopstalesVerified publisher2.5.12 of 2See more

kyverno devopstales 2.5.1

2 of the 2 container images this version deploys carry CVE-2026-39395.

Container imageDigestPackageFixed in
ghcr.io/kyverno/kyverno:v1.7.19c73f1841ebc
github.com/sigstore/cosign@v1.8.0
2.6.3
ghcr.io/kyverno/kyvernopre:v1.7.1185d2eebc60c
github.com/sigstore/cosign@v1.8.0
2.6.3

Open the chart page →

4,722
harborgpg-dev1.18.31 of 8See more

harbor gpg-dev 1.18.3

1 of the 8 container images this version deploys carry CVE-2026-39395.

Container imageDigestPackageFixed in
goharbor/trivy-adapter-photon:v2.14.35c6f7162804c
github.com/sigstore/cosign/v2@v2.6.2
2.6.3

Open the chart page →

3,376
harborhelm-harborVerified publisher2.3.51 of 8See more

harbor helm-harbor 2.3.5

1 of the 8 container images this version deploys carry CVE-2026-39395.

Container imageDigestPackageFixed in
goharbor/trivy-adapter-photon:v2.15.2215c07b71c37
github.com/sigstore/cosign/v2@v2.6.2
2.6.3

Open the chart page →

1,650
deploydefenderk8s-custom-controllerVerified publisher0.1.31 of 1See more

deploydefender k8s-custom-controller 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-39395.

Container imageDigestPackageFixed in
ghcr.io/manzil-infinity180/deploydefender:ea3ab0bb646cdbeddd1aca483ecf650f9ac0d0847fbc6855c8b3
github.com/sigstore/cosign/v2@v2.2.4
2.6.3

Open the chart page →

1,893
agent-control-cdnewrelic1.0.01 of 3See more

agent-control-cd newrelic 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39395.

Container imageDigestPackageFixed in
ghcr.io/fluxcd/source-controller:v1.5.000cd9316a379
github.com/sigstore/cosign/v2@v2.4.1
2.6.3

Open the chart page →

5,034
redhat-trusted-application-pipelineopenshift1.0.21 of 2See more

redhat-trusted-application-pipeline openshift 1.0.2

1 of the 2 container images this version deploys carry CVE-2026-39395.

Container imageDigestPackageFixed in
quay.io/redhat-appstudio/appstudio-utils:dbbdd82734232e6289e8fbae5b4c858481a7c0577b4202c25b67
github.com/sigstore/cosign/v2@v2.2.0
2.6.3

Open the chart page →

8,599
sigstore-probersigstoreVerified publisher0.3.11 of 1See more

sigstore-prober sigstore 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-39395.

Container imageDigestPackageFixed in
ghcr.io/sigstore/sigstore-probers/prober:v1.0.1d1e914e6d6b9
github.com/sigstore/cosign/v3@v3.0.4
3.0.6

Open the chart page →

424
harborwenerme1.19.21 of 8See more

harbor wenerme 1.19.2

1 of the 8 container images this version deploys carry CVE-2026-39395.

Container imageDigestPackageFixed in
goharbor/trivy-adapter-photon:v2.15.2215c07b71c37
github.com/sigstore/cosign/v2@v2.6.2
2.6.3

Open the chart page →

1,650

Container images carrying it

18 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
goharbor/trivy-adapter-photon:v2.15.2215c07b71c37
github.com/sigstore/cosign/v2@v2.6.2
2.6.3
3
aquasec/trivy:0.69.3bcc376de8d77
github.com/sigstore/cosign/v2@v2.6.2
2.6.3
1
artifacthub/hub:v1.19.0111918d8c399
github.com/sigstore/cosign@v1.13.6
2.6.3
1
artifacthub/scanner:v1.23.02d8365601f0e
github.com/sigstore/cosign/v2@v2.6.2
2.6.3
1
artifacthub/scanner:v1.19.0323d026e78c3
github.com/sigstore/cosign@v1.13.6
2.6.3
1
artifacthub/tracker:v1.19.06596c8c4d955
github.com/sigstore/cosign@v1.13.6
2.6.3
1
dongjiang1989/cosign-webhook:v1.1.02a3ead6a55dc
github.com/sigstore/cosign/v2@v2.1.1
2.6.3
1
goharbor/trivy-adapter-photon:v2.14.35c6f7162804c
github.com/sigstore/cosign/v2@v2.6.2
2.6.3
1
prowlercloud/prowler-api:5.31.14f252d579be2
github.com/sigstore/cosign/v2@v2.6.2
2.6.3
1
ghcr.io/fluxcd/source-controller:v1.5.000cd9316a379
github.com/sigstore/cosign/v2@v2.4.1
2.6.3
1
ghcr.io/kgma74/dockyard:0.4.0b40439329191
github.com/sigstore/cosign/v2@v2.2.4
2.6.3
1
ghcr.io/kyverno/kyverno:v1.7.19c73f1841ebc
github.com/sigstore/cosign@v1.8.0
2.6.3
1
ghcr.io/kyverno/kyvernopre:v1.7.1185d2eebc60c
github.com/sigstore/cosign@v1.8.0
2.6.3
1
ghcr.io/manzil-infinity180/deploydefender:ea3ab0bb646cdbeddd1aca483ecf650f9ac0d0847fbc6855c8b3
github.com/sigstore/cosign/v2@v2.2.4
2.6.3
1
ghcr.io/sigstore/policy-controller/policy-controller0bcd60beb93f
github.com/sigstore/cosign/v2@v2.5.0
2.6.3
1
ghcr.io/sigstore/sigstore-probers/prober:v1.0.1d1e914e6d6b9
github.com/sigstore/cosign/v3@v3.0.4
3.0.6
1
ghcr.io/spiffe/spire-agent:1.6.062517726d0c4
github.com/sigstore/cosign@v1.13.1
2.6.3
1
quay.io/redhat-appstudio/appstudio-utils:dbbdd82734232e6289e8fbae5b4c858481a7c0577b4202c25b67
github.com/sigstore/cosign/v2@v2.2.0
2.6.3
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.