VDB

GO-2024-2472

GO-2024-2472 PUBLISHED

Go package github.com/notaryproject/notation configured with permissive trust policies potentially susceptible to rollback attack from compromised registry

Affected Products

VendorProductVersions
github.comnotaryproject/notation0, 0
chainguardxeol0
wolfixeol0, 0, 0
chainguardxeol-fips0

Timeline

  • Jun 28, 2024 CVE Published
  • Mar 3, 2026 CVE Updated
  • May 18, 2026 Security Advisory
Open in Interactive Console →
$ Console Community · 100/wk Open console ›