CVE-2024-56138 | Timestamp signature generation lacks certificate revocation check in notion-go

notion-go is a collection of libraries for supporting sign and verify OCI artifacts. Based on Notary Project specifications. This issue was identified during Quarkslab's audit of the timestamp feature. During the timestamp signature generation, the revocation status of the certificate(s) used to generate the timestamp signature was not verified. During timestamp signature generation, notation-go did not check the revocation status of the certificate chain used by the TSA. This oversight creates a vulnerability that could be exploited through a Man-in-The-Middle attack. An attacker could potentially use a compromised, intermediate, or revoked leaf certificate to generate a malicious countersignature, which would then be accepted and stored by `notation`. This could lead to denial of service scenarios, particularly in CI/CD environments during signature verification processes because timestamp signature would fail due to the presence of a revoked certificate(s) potentially disrupting operations. This issue has been addressed in release version 1.3.0-rc.2 and all users are advised to upgrade. There are no known workarounds for this vulnerability.

Published: 2025-01-13 Last update: 2026-04-15 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2024-56138 is rated Low Risk (17.1/100): CVSS Medium severity, with low exploitation likelihood (EPSS 0.13%). Mandatory action: Low composite risk—no urgent action required; patch on your normal maintenance cycle and revisit priority if CVSS or EPSS increases.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Exploit prediction scoring system (EPSS) score for CVE-2024-56138

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2026-06-15 0.04% 0.13% +0.09%
2 2025-01-14 0.04%

Full EPSS history (2 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2024-56138

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
4.0 3.1 MEDIUM
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L Click to expand
Attack vector (AV:L)
They already need access on the box, or another person has to do something wrong; it’s not a remote drive-by.
Attack complexity (AC:L)
Once they can reach the bug, pulling it off is straightforward—no weird race conditions or rare setup.
Privileges required (PR:N)
No account or special rights needed—anonymous or random user is enough.
User interaction (UI:N)
Nobody has to click “OK” or open a trap file; it can work without a victim helping.
Scope (S:U)
Damage stays in the same “trust bubble” as the broken component—no big spill into unrelated systems.
Confidentiality (C:N)
Doesn’t really leak secrets in a meaningful way.
Integrity (I:N)
Data isn’t meaningfully altered or forged.
Availability (A:L)
Might cause slowdowns, glitches, or partial disruption—not a full brick.
2.5 1.4 [email protected]

Weakness enumeration for CVE-2024-56138

GitHub Security Advisory for CVE-2024-56138

GHSA-45v3-38pc-874v · Severity: medium · Ecosystem: go — notation-go's timestamp signature generation lacks certificate revocation check

OS Trackers for CVE-2024-56138

vendor priority summary link
debian not yet assigned CVE-2024-56138 not yet assigned priority: Debian including 1 source packages (golang-github-notaryproject-notation-go), 2 status rows across 2 suites (forky, sid): resolved 2. https://security-tracker.debian.org/tracker/CVE-2024-56138
ubuntu medium CVE-2024-56138 medium priority: Ubuntu including 2 source packages (golang-github-notaryproject-notation, golang-github-notaryproject-notation-go), 14 status rows across 7 suites (focal, jammy, noble, oracular, plucky, questing, upstream): DNE 8, needs-triage 4, ignored 2. https://ubuntu.com/security/CVE-2024-56138

Affected software / configurations for CVE-2024-56138

Vendor Product Version Raw CPE
No affected products in dataset.

References for CVE-2024-56138

cvelogic Threat Intelligence