Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-7rmh-48mx-2vwc | gitsign verify accepts signatures over go-git-normalized bytes, enabling trust confusion on malformed commits |
Fri, 15 May 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 15 May 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sigstore
Sigstore gitsign |
|
| Vendors & Products |
Sigstore
Sigstore gitsign |
Fri, 15 May 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Gitsign is a keyless Sigstore to signing tool for Git commits with your a GitHub / OIDC identity. Prior to 0.16.0, gitsign verify and gitsign verify-tag re-encode commit/tag objects through go-git's EncodeWithoutSignature before checking the signature, instead of verifying against the raw git object bytes. For malformed objects with duplicate tree headers, git-core and go-git parse different trees: git-core uses the first, go-git uses the second. A signature crafted over the go-git-normalized form (second tree) passes gitsign verify while git-core resolves the commit to a completely different tree. This breaks the invariant that a verified signature, the commit semantics git-core presents to users, and the object hash logged in Rekor all refer to the same content. This vulnerability is fixed in 0.16.0. | |
| Title | gitsign verify accepts signatures over go-git-normalized bytes, enabling trust confusion on malformed commits | |
| Weaknesses | CWE-295 CWE-347 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-05-15T17:43:59.446Z
Reserved: 2026-05-05T19:00:06.021Z
Link: CVE-2026-44309
Updated: 2026-05-15T17:42:44.620Z
Status : Received
Published: 2026-05-15T17:16:47.297
Modified: 2026-05-15T18:16:25.703
Link: CVE-2026-44309
No data.
OpenCVE Enrichment
Updated: 2026-05-15T17:30:04Z
Github GHSA