github.com/anchore/quill
Go3 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting github.com/anchore/quillpage 1 of 1
- CVE-2026-31959MEDIUMCVSS 5.3EG 5.3✓ Fixed in 0.7.12026-03-11
Quill provides simple mac binary signing and notarization from any platform. Quill before version v0.7.1 contains a Server-Side Request Forgery (SSRF) vulnerability when attempting to fetch the Apple notarization submission logs. Exploitat…
- CVE-2026-31960MEDIUMCVSS 5.3EG 5.3✓ Fixed in 0.7.12026-03-11
Quill provides simple mac binary signing and notarization from any platform. Quill before version v0.7.1 has unbounded reads of HTTP response bodies during the Apple notarization process. Exploitation requires the ability to modify API res…
- CVE-2026-31961MEDIUMCVSS 5.5EG 5.5✓ Fixed in 0.7.12026-03-11
Quill provides simple mac binary signing and notarization from any platform. Quill before version v0.7.1 contains an unbounded memory allocation vulnerability when parsing Mach-O binaries. Exploitation requires that Quill processes an atta…
Check whether github.com/anchore/quill is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for github.com/anchore/quill CVEs against the assets you own.
Start Free Scan →