An attacker who controls a remote registry can return a high number of attestations and/or signatures to cosign. This can cause cosign to enter a long loop resulting in a denial of service, i.e., endless data attack.
{ "review_status": "REVIEWED", "url": "https://pkg.go.dev/vuln/GO-2023-2181" }