CVE-2026-31960Disclosure(anchore / quill)

LOWCVSS 5.3 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Quill provides simple mac binary signing and notarization from any platform. Quill before version v0.7.1 has unbounded reads of HTTP response bodies during the Apple notarization process. Exploitation requires the ability to modify API responses from Apple's notarization service, which is not possible under standard network conditions due to HTTPS with proper TLS certificate validation; however, environments with TLS-intercepting proxies (common in corporate networks), compromised certificate authorities, or other trust boundary violations are at risk. When processing HTTP responses during notarization, Quill reads the entire response body into memory without any size limit. An attacker who can control or modify the response content can return an arbitrarily large payload, causing the Quill client to run out of memory and crash. The impact is limited to availability; there is no effect on confidentiality or integrity. Both the Quill CLI and library are affected when used to perform notarization operations. This vulnerability is fixed in 0.7.1.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-770

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • quill

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-03-11); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
quill

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-03-11: 2Mentions · 2026-03-12: 1Technical Details · 2026-03-11: 2Technical Details · 2026-03-12: 103-1103-12
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-112
Disclosure2
2026-03-121
General1
Full discourse3 posts
  • DailyCVE@dailycve
    General

    🟠 https://dailycve.com/quill-unbounded-read-#cve-2026-31960-medium/ Argo Workflows, Security Bypass, CVE-2026-31892 (Critical)

    Post summary

    The post links to a CVE announcement and lists two CVE identifiers with basic technical labels but does not provide PoC, exploit code, active exploitation evidence, or patch information.

    0000032
    167 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-31960 Quill provides simple mac binary signing and notarization from any platform. Quill before version v0.7.1 has unbounded reads of HTTP response bodies during the Apple … https://www.cve.org/CVERecord?id=CVE-2026-31960 ----- Traducción: CVE-2026-31960 Qui… http://infoflow.cloud`

    Post summary

    The tweet announces CVE‑2026‑31960, describing an unbounded HTTP response read in Quill versions prior to v0.7.1, with no evidence of a PoC, exploit, or patch available.

    0000025
    57 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-31960 Quill provides simple mac binary signing and notarization from any platform. Quill before version v0.7.1 has unbounded reads of HTTP response bodies during the Apple … https://www.cve.org/CVERecord?id=CVE-2026-31960

    Post summary

    The message announces CVE-2026-31960, describing an unbounded read vulnerability in Quill versions before v0.7.1, without presenting a PoC, exploit code, or patch details.

    00000165
    56.6K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appanchorequill---

Explore more