CLEANSTART-2026-HX30295

See a problem?
Import Source
https://github.com/cleanstart-dev/cleanstart-security-advisories/blob/main/advisories/2026/CLEANSTART-2026-HX30295.json
JSON Data
https://api.test.osv.dev/v1/vulns/CLEANSTART-2026-HX30295
Upstream
  • ghsa-3fxj-6jh8-hvhx
  • ghsa-9g5q-2w5x-hmxf
  • ghsa-rjr7-jggh-pgcp
Published
2026-09-01T11:17:16Z
Modified
2026-09-04T13:31:17Z
Summary
Security fixes in cosign 2.6.5-r0
Details

Package cosign version 2.6.5-r0 fixes 4 vulnerabilities: CVE-2026-49478, ghsa-3fxj-6jh8-hvhx, ghsa-9g5q-2w5x-hmxf, ghsa-rjr7-jggh-pgcp

References

Affected packages

CleanStart / cosign

Package

Name
cosign

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.6.5-r0

Affected versions

2.*
2.6.5-r0

Database specific

source
"https://github.com/cleanstart-dev/cleanstart-security-advisories/blob/main/advisories/2026/CLEANSTART-2026-HX30295.json"