{"id":"SUSE-SU-2026:20904-1","summary":"Security update for cosign","details":"This update for cosign fixes the following issues:\n\nUpdate to version 3.0.5:\n\n- CVE-2026-24122: Fixed improper validation of certificates that outlive\n  expired CA certificates (bsc#1258542)\n- CVE-2026-26958: Fixed filippo.io/edwards25519: failure to initialize receiver\n  in MultiScalarMult can produce invalid results and lead to undefined behavior\n  (bsc#1258612)\n- CVE-2026-24137: Fixed github.com/sigstore/sigstore/pkg/tuf: legacy TUF client\n  allows for arbitrary file writes with target cache path traversal\n  (bsc#1257139)\n- CVE-2026-22772: Fixed github.com/sigstore/fulcio: bypass MetaIssuer URL\n  validation bypass can trigger SSRF to arbitrary internal services\n  (bsc#1256562)\n- CVE-2026-23991: Fixed github.com/theupdateframework/go-tuf/v2: denial of\n  service due to invalid TUF metadata JSON returned by TUF repository\n  (bsc#1257080)\n- CVE-2026-23992: Fixed github.com/theupdateframework/go-tuf/v2: unauthorized\n  modification to TUF metadata files due to a compromised or misconfigured TUF\n  repository (bsc#1257085)\n- CVE-2025-11065: Fixed github.com/go-viper/mapstructure/v2: sensitive\n  Information leak in logs (bsc#1250620)\n- CVE-2026-22703: Fixed that cosign verification accepts any valid Rekor entry\n  under certain conditions (bsc#1256496)\n- CVE-2025-58181: Fixed golang.org/x/crypto/ssh: invalidated number of\n  mechanisms can cause unbounded memory consumption (bsc#1253913)\n","modified":"2026-04-02T17:33:48.756256Z","published":"2026-03-18T11:27:44Z","related":["CVE-2025-11065","CVE-2025-58181","CVE-2026-22703","CVE-2026-22772","CVE-2026-23991","CVE-2026-23992","CVE-2026-24122","CVE-2026-24137","CVE-2026-26958"],"upstream":["CVE-2025-11065","CVE-2025-58181","CVE-2026-22703","CVE-2026-22772","CVE-2026-23991","CVE-2026-23992","CVE-2026-24122","CVE-2026-24137","CVE-2026-26958"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-202620904-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1250620"},{"type":"REPORT","url":"https://bugzilla.suse.com/1253913"},{"type":"REPORT","url":"https://bugzilla.suse.com/1256496"},{"type":"REPORT","url":"https://bugzilla.suse.com/1256562"},{"type":"REPORT","url":"https://bugzilla.suse.com/1257080"},{"type":"REPORT","url":"https://bugzilla.suse.com/1257085"},{"type":"REPORT","url":"https://bugzilla.suse.com/1257139"},{"type":"REPORT","url":"https://bugzilla.suse.com/1258542"},{"type":"REPORT","url":"https://bugzilla.suse.com/1258612"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-11065"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-58181"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-22703"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-22772"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23991"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23992"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-24122"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-24137"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-26958"}],"affected":[{"package":{"name":"cosign","ecosystem":"SUSE:Linux Enterprise Server 16.0","purl":"pkg:rpm/suse/cosign&distro=SUSE%20Linux%20Enterprise%20Server%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.0.5-160000.1.1"}]}],"ecosystem_specific":{"binaries":[{"cosign":"3.0.5-160000.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:20904-1.json"}},{"package":{"name":"cosign","ecosystem":"SUSE:Linux Enterprise Server for SAP applications 16.0","purl":"pkg:rpm/suse/cosign&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20applications%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.0.5-160000.1.1"}]}],"ecosystem_specific":{"binaries":[{"cosign":"3.0.5-160000.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:20904-1.json"}}],"schema_version":"1.7.5"}