CVE-2026-24122 | sigstore cosign up to 3.0.4 Certificate Chain certificate validation (GHSA-wfqv-66vq-46rm)
A vulnerability, which was classified as critical, was found in sigstore cosign up to 3.0.4. This impacts an unknown function of the component Certificate Chain Handler. Such manipulation leads to improper certificate validation.
This vulnerability is listed as CVE-2026-24122. The attack may be performed from remote. There is no available exploit.
You should upgrade the affected component.