Notaryproject develops signing and verification tooling for container and artifact integrity, with its exposure concentrated in the notation-go library that implements the Notary v2 specification. The recurring vulnerability pattern centers on resource-handling and cryptographic-verification weaknesses, including uncontrolled resource consumption, improper exception handling, and signature-validation gaps that reflect the complexity of parsing and validating cryptographic containers. Current severity, exploitation status, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Notaryproject over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-33959HIGH notation is a CLI tool to sign and verify OCI artifacts and container images. An attacker who has compromised a registry can cause users to verify the wrong artifact. The problem h | Jun 6, 2023 | 8.8 | 27 | NO | NO |
CVE-2023-25656HIGH notation-go is a collection of libraries for supporting Notation sign, verify, push, and pull of oci artifacts. Prior to version 1.0.0-rc.3, notation-go users will find their appli | Feb 20, 2023 | 7.5 | 23 | NO | NO |
CVE-2023-33958MEDIUM notation is a CLI tool to sign and verify OCI artifacts and container images. An attacker who has compromised a registry and added a high number of signatures to an artifact can ca | Jun 6, 2023 | 6.5 | 20 | NO | NO |
CVE-2023-33957MEDIUM notation is a CLI tool to sign and verify OCI artifacts and container images. An attacker who has compromised a registry and added a high number of signatures to an artifact can ca | Jun 6, 2023 | 5.7 | 19 | NO | NO |
CVE-2024-23332MEDIUM The Notary Project is a set of specifications and tools intended to provide a cross-industry standard for securing software supply chains by using authentic container images and ot | Jan 19, 2024 | 6.8 | 18 | NO | NO |
notion-go is a collection of libraries for supporting sign and verify OCI artifacts. Based on Notary Project specifications. The issue was identified during Quarkslab's security au | Jan 13, 2025 | 3.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Notaryproject.
Media articles that mention a CVE ID that affects a product developed by Notaryproject — matched by CVE ID, not by vendor name.