Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
light_mode
dark_mode
ECHO-da76-7fca-1d02
See a problem?
Import Source
https://advisory.echohq.com/osv/ECHO-da76-7fca-1d02.json
JSON Data
https://api.osv.dev/v1/vulns/ECHO-da76-7fca-1d02
Upstream
CVE-2026-39395
GHSA-w6c6-c85g-mmv6
Published
2026-09-28T00:01:31Z
Modified
2026-09-28T00:45:35Z
Summary
[none]
Details
References
https://advisory.echohq.com/cve/CVE-2026-39395
https://github.com/sigstore/cosign/security/advisories/GHSA-w6c6-c85g-mmv6
Affected packages
Echo:Go
/
github.com/sigstore/cosign/v2
Package
Name
github.com/sigstore/cosign/v2
Purl
pkg:golang/github.com/sigstore/cosign/v2
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
2.6.3-1
Database specific
source
"https://advisory.echohq.com/osv/ECHO-da76-7fca-1d02.json"
ECHO-da76-7fca-1d02 - OSV