notaryproject has 3 CVEs on record between 2023 and 2025. The median CVSS is 4.0 (medium). Most affected products: github.com/notaryproject/notation-go (2), github.com/notaryproject/notation (1).
CVEs per month
Last 12 months, by publish date
1025/101125/111225/120126/010226/020326/030426/040526/050626/060726/070826/080926/09
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 4.0
- Publish → KEV
- —
- Last 90 days
- 0 prev 0
Products
- github.com/notaryproject/notation-go 2
- github.com/notaryproject/notation 1
3
Total CVEs
0
Critical
0
CISA KEV
0
Exploited
Worst active — by depth score
CVE-2023-25656High· 7.5notation-go has excessive memory allocation on verification41CVE-2024-56138Medium· 4.0notation-go's timestamp signature generation lacks certificate revocation check22CVE-2024-23332Medium· 4.0Go package github.com/notaryproject/notation configured with permissive trust policies potentially susceptible to rollback attack from co…22
notaryproject vulnerabilities
CVEs affecting notaryproject, newest first. Open any entry for full detail, references, and exploit status.
3 CVEsRSS
CVE-2024-56138Medium· 4.0notation-go's timestamp signature generation lacks certificate revocation check
notation-go's timestamp signature generation lacks certificate revocation check
▾ Sunlitnotaryproject · github.com/notaryproject/notation-goEPSS 0.13%via OSV
CVE-2024-23332Medium· 4.0Go package github.com/notaryproject/notation configured with permissive trust policies potentially susceptible to rollback attack from co…
Go package github.com/notaryproject/notation configured with permissive trust policies potentially susceptible to rollback attack from compromised registry
▾ Sunlitnotaryproject · github.com/notaryproject/notationEPSS 0.29%via OSV
CVE-2023-25656High· 7.5notation-go has excessive memory allocation on verification
notation-go has excessive memory allocation on verification
▾ Twilightnotaryproject · github.com/notaryproject/notation-goEPSS 0.44%via OSV