Quill vulnerable to SSRF via unvalidated URL from Apple notarization log retrieval in github.com/anchore/quill
{ "url": "https://pkg.go.dev/vuln/GO-2026-4671", "review_status": "UNREVIEWED" }
"https://vuln.go.dev/ID/GO-2026-4671.json"