Sigstore vulnerabilities
29 CVEs affecting Sigstore products, 0 known to be exploited (CISA KEV), with EPSS scores. Most affected: Cosign, Gitsign, Sigstore-Js, Sigstore-Go, Sigstore-Java.
- Cosign: 9 CVEs
- Gitsign: 4 CVEs
- Sigstore-Js: 4 CVEs
- Sigstore-Go: 3 CVEs
- Sigstore-Java: 3 CVEs
- Sigstore: 2 CVEs
- Fulcio: 1 CVE
- Policy Controller: 1 CVE
- Rekor: 1 CVE
- Sigstore-Python: 1 CVE