CVE-2023-25656
HIGHnotation-go < 1.0.0-rc.3 - Denial of Service via Excessive Memory Consumption
Title source: llmDescription
notation-go is a collection of libraries for supporting Notation sign, verify, push, and pull of oci artifacts. Prior to version 1.0.0-rc.3, notation-go users will find their application using excessive memory when verifying signatures. The application will be killed, and thus availability is impacted. The problem has been patched in the release v1.0.0-rc.3. Some workarounds are available. Users can review their own trust policy file and check if the identity string contains `=#`. Meanwhile, users should only put trusted certificates in their trust stores referenced by their own trust policy files, and make sure the `authenticity` validation is set to `enforce`.
References (2)
Core 2
Core References
Scores
CVSS v3
7.5
EPSS
0.0044
EPSS Percentile
35.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-770
Status
published
Products (4)
notaryproject/notation-go
0.7.0 alpha1
notaryproject/notation-go
0.8.0 alpha1
notaryproject/notation-go
0.9.0 alpha1
notaryproject/notation-go
0 - 1.0.0-rc.3Go
Published
Feb 20, 2023
Tracked Since
Feb 18, 2026