blob: 1addd28dbfd643b0cae4442f65c7bb5de2773e30 [file]
id: GO-2026-4675
modules:
- module: github.com/anchore/quill
versions:
- fixed: 0.7.1
vulnerable_at: 0.7.0
summary: |-
Quill has unbounded memory allocation via unvalidated size fields in Mach-O
binary parsing in github.com/anchore/quill
cves:
- CVE-2026-31961
ghsas:
- GHSA-xj69-m9qq-8m94
references:
- advisory: https://github.com/anchore/quill/security/advisories/GHSA-xj69-m9qq-8m94
- advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-31961
- fix: https://github.com/anchore/quill/commit/80cf3fe082678af0ec4f9f8dd93f39189d2dc1fe
- web: https://developer.apple.com/documentation/technotes/tn3126-inside-code-signing-hashes
- web: https://github.com/anchore/quill/releases/tag/v0.7.1
source:
id: GHSA-xj69-m9qq-8m94
created: 2026-03-12T19:42:23.338991732Z
review_status: UNREVIEWED