LIVE · cybersecurity feed
Live wire
cve recordmedium

CVE-2026-31959

anchore · quill

Published
CVSS5.3
Severitymedium
WeaknessCWE-918
ExploitedNot in CISA KEV

CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

Description

Quill provides simple mac binary signing and notarization from any platform. Quill before version v0.7.1 contains a Server-Side Request Forgery (SSRF) vulnerability when attempting to fetch the Apple notarization submission logs. Exploitation requires the ability to modify API responses from Apple's notarization service, which is not possible under standard network conditions due to HTTPS with proper TLS certificate validation; however, environments with TLS-intercepting proxies (common in corporate networks), compromised certificate authorities, or other trust boundary violations are at risk. When retrieving submission logs, Quill fetches a URL provided in the API response without validatin

References

← Back to the CVE Tracker

Our coverage of CVE-2026-31959

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-31959.