{"id":"GHSA-pmwq-pjrm-6p5r","summary":"in-toto-golang and in-toto-python have inconsistent negation behavior","details":"### Impact\n_What kind of vulnerability is it? Who is impacted?_\n\nin-toto-golang and in-toto-python both support glob patterns in artifact rules to indicate the artifacts that a rule applies to. Both support negations in character classes to indicate what should *not* be matched, but they used different operators to indicate the negation. in-toto-python uses `!` while in-toto-golang used `^`. A layout authored with the expectations of one implementation can therefore exhibit different behavior in the other implementation.\n\nThis impacts users in a specific set of circumstances where two different implementations are used to verify the same layout + attestation bundle at different stages of the same pipeline. As a rule of thumb, we advise using a single implementation across all aspects of a pipeline, from layout creation to pipeline execution and verification to prevent this class of bugs.\n\n### Patches\n_Has the problem been patched? What versions should users upgrade to?_\n\nin-toto-golang has been updated to use `!` instead of `^` to indicate negation. See https://github.com/in-toto/in-toto-golang/pull/462. This is part of v0.11.0.","aliases":["GO-2026-5547"],"modified":"2026-09-10T03:51:06.602952009Z","published":"2026-05-08T22:24:19Z","database_specific":{"nvd_published_at":null,"cwe_ids":["CWE-168"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-05-08T22:24:19Z"},"references":[{"type":"WEB","url":"https://github.com/in-toto/in-toto-golang/security/advisories/GHSA-pmwq-pjrm-6p5r"},{"type":"WEB","url":"https://github.com/in-toto/in-toto-golang/pull/462"},{"type":"WEB","url":"https://github.com/in-toto/in-toto-golang/commit/36d782ffb2ca3adbffcdce1fd971c23319dd4469"},{"type":"PACKAGE","url":"https://github.com/in-toto/in-toto-golang"}],"affected":[{"package":{"name":"github.com/in-toto/in-toto-golang","ecosystem":"Go","purl":"pkg:golang/github.com/in-toto/in-toto-golang"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.11.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-pmwq-pjrm-6p5r/GHSA-pmwq-pjrm-6p5r.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:N"}]}