Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
0 Quill provides simple mac binary signing and notarization from any platform. Quill before version v0.7.1 contains an unbounded memory allocation vulnerability when parsing Mach-O binaries. Exploitation requires that Quill processes an attacker-supplied Mach-O binary, which is most likely in environments such as CI/CD pipelines, shared signing services, or any workflow where externally-submitted binaries are accepted for signing. When parsing a Mach-O binary, Quill reads several size and count fields from the LC_CODE_SIGNATURE load command and embedded code signing structures (SuperBlob, BlobIndex) and uses them to allocate memory buffers without validating that the values are reasonable or consistent with the actual file size. Affected fields include DataSize, DataOffset, and Size from the load command, Count from the SuperBlob header, and Length from individual blob headers. An attacker can craft a minimal (~4KB) malicious Mach-O binary with extremely large values in these fields, causing Quill to attempt to allocate excessive memory. This leads to memory exhaustion and denial of service, potentially crashing the host process. Both the Quill CLI and Go library are affected when used to parse untrusted Mach-O files. This vulnerability is fixed in 0.7.1. Join the discussion | CVE Database V5 | 03/11/2026, 19:32:28 UTC Added: 03/11/2026, 19:44:49 UTC |
0 CVE-2026-31960 is a medium-severity vulnerability in Anchore's Quill tool (versions before 0.7.1) that causes unbounded memory consumption during the Apple notarization process. Quill reads the entire HTTP response body from Apple's notarization service without size limits, which can lead to out-of-memory crashes if an attacker controls the response content. Exploitation requires the ability to intercept or modify HTTPS traffic, which is generally prevented by TLS certificate validation but possible in environments with TLS interception proxies or compromised certificate authorities. The impact is limited to availability, causing denial of service on the Quill client or library during notarization. There is no impact on confidentiality or integrity. The vulnerability is fixed in version 0.7.1. Join the discussion | CVE Database V5 | 03/11/2026, 19:31:34 UTC Added: 03/11/2026, 19:44:49 UTC |
CVE-2026-31959 is a Server-Side Request Forgery (SSRF) vulnerability in Anchore's Quill tool prior to version 0.7.1. Quill fetches Apple notarization submission logs by following URLs provided in Apple's API responses without validating the URL scheme or host address. An attacker capable of tampering with these API responses—possible in environments with TLS interception, compromised CAs, or trust boundary violations—can supply arbitrary URLs, causing Quill to make HTTP(S) requests to attacker-controlled or internal network resources. This may lead to exfiltration of sensitive data such as cloud credentials or internal service information. Both the Quill CLI and library are affected. The vulnerability has a CVSS score of 5.3 (medium severity) and requires network-level manipulation of API responses, which is non-trivial under normal conditions. The issue is fixed in Quill version 0. Join the discussion | CVE Database V5 | 03/11/2026, 19:30:46 UTC Added: 03/11/2026, 19:44:49 UTC |
0 A lack of data validation vulnerability in the HTML export feature in Quill in allows Cross-Site Scripting (XSS). This issue affects Quill: 2.0.3. Join the discussion | CVE Database V5 | 01/13/2026, 20:39:29 UTC Added: 01/13/2026, 20:56:34 UTC |
Showing 1 to 4 of 4 results