github.com/notaryproject/notation-go vulnerabilities
CVEs whose affected-version data names the github.com/notaryproject/notation-go package (go). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2024-56138Medium· 4.0notation-go's timestamp signature generation lacks certificate revocation check
notation-go's timestamp signature generation lacks certificate revocation check
▾ Sunlitnotaryproject · github.com/notaryproject/notation-goEPSS 0.13%via OSV
CVE-2023-25656High· 7.5notation-go has excessive memory allocation on verification
notation-go has excessive memory allocation on verification
▾ Twilightnotaryproject · github.com/notaryproject/notation-goEPSS 0.44%via OSV