CLEANSTART-2026-RI42866

See a problem?
Import Source
https://github.com/cleanstart-dev/cleanstart-security-advisories/blob/main/advisories/2026/CLEANSTART-2026-RI42866.json
JSON Data
https://api.osv.dev/v1/vulns/CLEANSTART-2026-RI42866
Upstream
  • ghsa-273p-m2cw-6833
Published
2026-09-18T10:28:47Z
Modified
2026-09-18T11:47:33Z
Summary
Security fix for ghsa-273p-m2cw-6833 applied in: cosign 2.4.3-r0, cosign 2.5.3-r0, kubescape 3.0.47-r0, kyverno-fips 1.16.1-r2, spire-server 1.14.1-r1, spire-server-fips 1.14.1-r1, tekton-chains 0.26.0-r2, tekton-chains-fips 0.26.0-r2, tkn-fips 0.43.0-r2
Details

ghsa-273p-m2cw-6833 affects multiple packages. This issue is resolved in later releases. See references for individual vulnerability details.

References

Affected packages

CleanStart
cosign

Package

Name
cosign

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.4.3-r0

Database specific

source
"https://github.com/cleanstart-dev/cleanstart-security-advisories/blob/main/advisories/2026/CLEANSTART-2026-RI42866.json"
cosign

Package

Name
cosign

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.5.3-r0

Database specific

source
"https://github.com/cleanstart-dev/cleanstart-security-advisories/blob/main/advisories/2026/CLEANSTART-2026-RI42866.json"
kubescape

Package

Name
kubescape

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.0.47-r0

Database specific

source
"https://github.com/cleanstart-dev/cleanstart-security-advisories/blob/main/advisories/2026/CLEANSTART-2026-RI42866.json"
kyverno-fips

Package

Name
kyverno-fips

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.16.1-r2

Database specific

source
"https://github.com/cleanstart-dev/cleanstart-security-advisories/blob/main/advisories/2026/CLEANSTART-2026-RI42866.json"
spire-server

Package

Name
spire-server

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.14.1-r1

Database specific

source
"https://github.com/cleanstart-dev/cleanstart-security-advisories/blob/main/advisories/2026/CLEANSTART-2026-RI42866.json"
spire-server-fips

Package

Name
spire-server-fips

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.14.1-r1

Database specific

source
"https://github.com/cleanstart-dev/cleanstart-security-advisories/blob/main/advisories/2026/CLEANSTART-2026-RI42866.json"
tekton-chains

Package

Name
tekton-chains

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.26.0-r2

Database specific

source
"https://github.com/cleanstart-dev/cleanstart-security-advisories/blob/main/advisories/2026/CLEANSTART-2026-RI42866.json"
tekton-chains-fips

Package

Name
tekton-chains-fips

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.26.0-r2

Database specific

source
"https://github.com/cleanstart-dev/cleanstart-security-advisories/blob/main/advisories/2026/CLEANSTART-2026-RI42866.json"
tkn-fips

Package

Name
tkn-fips

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.43.0-r2

Database specific

source
"https://github.com/cleanstart-dev/cleanstart-security-advisories/blob/main/advisories/2026/CLEANSTART-2026-RI42866.json"