{"id":"GO-2023-1832","summary":"Verification bypass in github.com/notaryproject/notation-go","details":"An attacker who controls or compromises a registry can lead a user to verify the wrong artifact.","aliases":["CVE-2023-33959","GHSA-xhg5-42rf-296r"],"modified":"2026-02-04T02:43:08.765429Z","published":"2023-06-26T16:53:25Z","related":["CGA-2qgm-6fxc-686h"],"database_specific":{"review_status":"REVIEWED","url":"https://pkg.go.dev/vuln/GO-2023-1832"},"references":[{"type":"ADVISORY","url":"https://github.com/notaryproject/notation-go/security/advisories/GHSA-xhg5-42rf-296r"},{"type":"FIX","url":"https://github.com/notaryproject/notation-go/commit/39c8ed050a65cca3f3f308534acb612096735a64"},{"type":"FIX","url":"https://github.com/notaryproject/notation-go/commit/eba60f5aed9c9e05dee55324423c95fe34700b4c"},{"type":"WEB","url":"https://github.com/notaryproject/notation-go/releases/tag/v1.0.0-rc.6"}],"affected":[{"package":{"name":"github.com/notaryproject/notation-go","ecosystem":"Go","purl":"pkg:golang/github.com/notaryproject/notation-go"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.0.0-rc.6"}]}],"ecosystem_specific":{"imports":[{"path":"github.com/notaryproject/notation-go","symbols":["Sign","Verify"]}]},"database_specific":{"source":"https://vuln.go.dev/ID/GO-2023-1832.json"}}],"schema_version":"1.7.3","credits":[{"name":"Adam Korczynski (@AdamKorcz)"},{"name":"Shiwei Zhang (@shizhMSFT)"},{"name":"Pritesh Bandi (@priteshbandi)"}]}