CVE Explorer
CVE-2026-31959
Quill provides simple mac binary signing and notarization from any platform. Quill before version v0.7.1 contains a Server-Side Request Forgery (SSRF) vulnerability when attempting to fetch the Apple notarization submission logs. Exploitation requires the ability to modify API responses from Apple's notarization service, which is not possible under standard network conditions due to HTTPS with proper TLS certificate validation; however, environments with TLS-intercepting proxies (common in corpo
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"quill","vendor":"anchore","versions":[{"status":"affected","version":"< 0.7.1"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:4febc577bd382d192c80561201cb769cd31a97843943b07f24445e6a21d4ba8e · sha256:fc31a1d50cc7d29b… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"HIGH","attackVector":"ADJACENT_NETWORK","availabilityImpact":"NONE","baseScore":5.3,"baseSeverity":"MEDIUM","confidentialityImpact":"HIGH","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:4febc577bd382d192c80561201cb769cd31a97843943b07f24445e6a21d4ba8e · sha256:fc31a1d50cc7d29b… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-918","description":"CWE-918: Server-Side Request Forgery (SSRF)","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:4febc577bd382d192c80561201cb769cd31a97843943b07f24445e6a21d4ba8e · sha256:fc31a1d50cc7d29b… · /containers/cna/problemTypes/0/descriptions/0
Source references
1 source assertion{"name":"https://github.com/anchore/quill/security/advisories/GHSA-7q3q-5px6-4c5p","tags":["x_refsource_CONFIRM"],"url":"https://github.com/anchore/quill/security/advisories/GHSA-7q3q-5px6-4c5p"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:4febc577bd382d192c80561201cb769cd31a97843943b07f24445e6a21d4ba8e · sha256:fc31a1d50cc7d29b… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.