Go package github.com/notaryproject/notation configured with permissive trust policies potentially susceptible to rollback attack from compromised registry
Modified: 9/10/2026
package
pkg:go/github.com/notaryproject/notation
Go package github.com/notaryproject/notation configured with permissive trust policies potentially susceptible to rollback attack from compromised registry
Modified: 9/10/2026
Notation vulnerable to denial of service from high number of artifact signatures
Modified: 8/20/2024
Notation's default `maxSignatureAttempts` in `notation verify` enables an endless data attack
Modified: 9/10/2026
Notation vulnerable to denial of service from high number of artifact signatures in github.com/notaryproject/notation
Modified: 3/3/2026
Notation's default `maxSignatureAttempts` in `notation verify` enables an endless data attack in github.com/notaryproject/notation
Modified: 3/3/2026
Go package github.com/notaryproject/notation configured with permissive trust policies potentially susceptible to rollback attack from compromised registry
Modified: 7/2/2026