{"id":"GO-2023-1589","summary":"Denial of service from memory exhaustion in github.com/notaryproject/notation-go","details":"Parsing PKIX distinguished names containing the string \"=#\" can cause excessive memory consumption.","aliases":["CVE-2023-25656","GHSA-87x9-7grx-m28v"],"modified":"2026-02-04T02:57:28.167652Z","published":"2023-07-11T18:44:01Z","related":["CGA-cx4p-wvhc-q6q3"],"database_specific":{"url":"https://pkg.go.dev/vuln/GO-2023-1589","review_status":"REVIEWED"},"references":[{"type":"FIX","url":"https://github.com/notaryproject/notation-go/pull/275"}],"affected":[{"package":{"name":"github.com/notaryproject/notation-go","ecosystem":"Go","purl":"pkg:golang/github.com/notaryproject/notation-go"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.0.0-rc.3"}]}],"ecosystem_specific":{"imports":[{"symbols":["ParseDistinguishedName"],"path":"github.com/notaryproject/notation-go/internal/pkix"},{"path":"github.com/notaryproject/notation-go/verifier","symbols":["New","NewFromConfig","verifier.Verify","verifyX509TrustedIdentities"]},{"path":"github.com/notaryproject/notation-go/verifier/trustpolicy","symbols":["Document.Validate","validateTrustedIdentities"]}]},"database_specific":{"source":"https://vuln.go.dev/ID/GO-2023-1589.json"}}],"schema_version":"1.7.3"}