Server-Side Request Forgery in Quill Affects Multiple Versions from Anchore
CVE-2026-31959

5.3MEDIUM

Key Information:

Vendor

Anchore

Status
Vendor
CVE Published:
11 March 2026

What is CVE-2026-31959?

Quill, a binary signing and notarization tool by Anchore, contains a vulnerability that allows Server-Side Request Forgery (SSRF) when fetching notarization submission logs. This flaw affects versions prior to v0.7.1 and arises from insufficient validation of API response URLs, allowing attackers to input malicious URLs. If exploited, this vulnerability could lead to sensitive data exposure, such as cloud provider credentials, particularly in environments with compromised network configurations or trust boundaries. Both the Quill CLI and library are at risk when handling notarization submissions.

Affected Version(s)

quill < 0.7.1

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.