{"id":"GO-2023-1589","summary":"Denial of service from memory exhaustion in github.com/notaryproject/notation-go","details":"Parsing PKIX distinguished names containing the string \"=#\" can cause excessive memory consumption.","aliases":["CVE-2023-25656","GHSA-87x9-7grx-m28v"],"modified":"2026-07-17T21:04:20.726502337Z","published":"2023-07-11T18:44:01Z","database_specific":{"review_status":"REVIEWED","url":"https://pkg.go.dev/vuln/GO-2023-1589"},"references":[{"type":"FIX","url":"https://github.com/notaryproject/notation-go/pull/275"}],"affected":[{"package":{"name":"github.com/notaryproject/notation-go","ecosystem":"Go","purl":"pkg:golang/github.com/notaryproject/notation-go"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.0.0-rc.3"}]}],"ecosystem_specific":{"imports":[{"path":"github.com/notaryproject/notation-go/internal/pkix","symbols":["ParseDistinguishedName"]},{"symbols":["New","NewFromConfig","verifier.Verify","verifyX509TrustedIdentities"],"path":"github.com/notaryproject/notation-go/verifier"},{"path":"github.com/notaryproject/notation-go/verifier/trustpolicy","symbols":["Document.Validate","validateTrustedIdentities"]}]},"database_specific":{"source":"https://vuln.go.dev/ID/GO-2023-1589.json"}}],"schema_version":"1.7.5"}