CVE Explorer
CVE-2026-31960
Quill provides simple mac binary signing and notarization from any platform. Quill before version v0.7.1 has unbounded reads of HTTP response bodies during the Apple notarization process. Exploitation requires the ability to modify API responses from Apple's notarization service, which is not possible under standard network conditions due to HTTPS with proper TLS certificate validation; however, environments with TLS-intercepting proxies (common in corporate networks), compromised certificate au
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"quill","vendor":"anchore","versions":[{"status":"affected","version":"< 0.7.1"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:9a1b1811e58538fa36986fef565821bce5c82e7b7a04c6cdcd6d6f5c773a7e16 · sha256:2c1dd6df92c4801a… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"HIGH","attackVector":"ADJACENT_NETWORK","availabilityImpact":"HIGH","baseScore":5.3,"baseSeverity":"MEDIUM","confidentialityImpact":"NONE","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:9a1b1811e58538fa36986fef565821bce5c82e7b7a04c6cdcd6d6f5c773a7e16 · sha256:2c1dd6df92c4801a… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-770","description":"CWE-770: Allocation of Resources Without Limits or Throttling","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:9a1b1811e58538fa36986fef565821bce5c82e7b7a04c6cdcd6d6f5c773a7e16 · sha256:2c1dd6df92c4801a… · /containers/cna/problemTypes/0/descriptions/0
Source references
1 source assertion{"name":"https://github.com/anchore/quill/security/advisories/GHSA-g32c-4pvp-769g","tags":["x_refsource_CONFIRM"],"url":"https://github.com/anchore/quill/security/advisories/GHSA-g32c-4pvp-769g"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:9a1b1811e58538fa36986fef565821bce5c82e7b7a04c6cdcd6d6f5c773a7e16 · sha256:2c1dd6df92c4801a… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.