An attacker who controls a remote registry can return a high number of attestations and/or signatures to cosign. This can cause cosign to enter a long loop resulting in a denial of service, i.e., endless data attack.
{
"url": "https://pkg.go.dev/vuln/GO-2023-2181",
"review_status": "REVIEWED"
}