LIVE · cybersecurity feed
Live wire
cve recordmedium

CVE-2026-31960

anchore · quill

Published
CVSS5.3
Severitymedium
WeaknessCWE-770
ExploitedNot in CISA KEV

CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

Description

Quill provides simple mac binary signing and notarization from any platform. Quill before version v0.7.1 has unbounded reads of HTTP response bodies during the Apple notarization process. Exploitation requires the ability to modify API responses from Apple's notarization service, which is not possible under standard network conditions due to HTTPS with proper TLS certificate validation; however, environments with TLS-intercepting proxies (common in corporate networks), compromised certificate authorities, or other trust boundary violations are at risk. When processing HTTP responses during notarization, Quill reads the entire response body into memory without any size limit. An attacker who

References

← Back to the CVE Tracker

Our coverage of CVE-2026-31960

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-31960.