Junglewise Threat Intelligence

CVE-2026-31959: Anchore Quill SSRF in Apple notarization log retrieval

CVE-2026-31959 · Severity: medium · CVSS 5.3 · Published 2026-03-11

Technologies: Anchore Quill, github.com/anchore/quill (Go). Vendors: Go.

Executive brief

Anchore Quill, a tool used for signing and notarizing macOS applications, is vulnerable to a security flaw when retrieving logs from Apple's notarization service. If an attacker can intercept or manipulate the network traffic between Quill and Apple, they can redirect the tool to request data from internal servers or malicious external sites. This could lead to the theft of sensitive information, such as cloud service credentials or internal company data.

Technical details

Quill versions prior to v0.7.1 are vulnerable to Server-Side Request Forgery (SSRF) during the retrieval of Apple notarization submission logs. The application fetches a URL provided in the Apple Notary API response without validating the protocol scheme (e.g., ensuring it is HTTPS) or verifying that the destination host is not a local or multicast IP address. Exploitation requires the ability to modify API responses, which typically necessitates a TLS-intercepting proxy, a compromised Certificate Authority, or a man-in-the-middle position within a trusted boundary. An attacker successfully manipulating the response can force the Quill client to issue requests to arbitrary internal or external destinations, potentially exfiltrating sensitive metadata or service responses. The issue is fixed in version 0.7.1.

Affected products

  • anchore quill < 0.7.1

Timeline

  • 2026-03-10: patched: Fixed in version v0.7.1
  • 2026-03-11: disclosed: GitHub Advisory published

References

Related threats