—
GO-2026-4671
Quill vulnerable to SSRF via unvalidated URL from Apple notarization log retrieval in github.com/anchore/quill
Quick fix
GO-2026-4671 — github.com/anchore/quill: upgrade to the fixed version with the command below.
go get github.com/anchore/quill@v0.7.1Details
Quill vulnerable to SSRF via unvalidated URL from Apple notarization log retrieval in github.com/anchore/quill
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/anchore/quill/security/advisories/GHSA-7q3q-5px6-4c5p[ADVISORY]
- https://nvd.nist.gov/vuln/detail/CVE-2026-31959[ADVISORY]
- https://github.com/anchore/quill/commit/e41d66a517c2dc20ad8e9fbccffbdc6ba5ef0020[FIX]
- https://developer.apple.com/documentation/notaryapi/get-submission-log[WEB]
- https://github.com/anchore/quill/releases/tag/v0.7.1[WEB]