cosign verify-attestation used with the --type flag will report a false positive verification when:
This can happen when signing with a standard keypair and with "keyless" signing with Fulcio. Users should upgrade to cosign version 1.10.1 or greater for a patch. Currently the only workaround is to upgrade.
{
    "nvd_published_at": "2022-08-04T19:15:00Z",
    "severity": "HIGH",
    "cwe_ids": [
        "CWE-347"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2022-08-10T18:40:38Z"
}