Git Security System Vulnerability in Gittuf Affects Push Access Control
CVE-2026-44544

4.9MEDIUM

Key Information:

Vendor

Gittuf

Status
Vendor
CVE Published:
14 May 2026

What is CVE-2026-44544?

The Gittuf platform-agnostic Git security system has a vulnerability that allows an attacker with push access to the Reference State Log (RSL) to manipulate the policy management of the system. By exploiting this flaw, the attacker can roll back the current security policy to any prior state that is still trusted by the existing root keys. This exploitation occurs when the system validates RSL entries without adequately safeguarding against unauthorized policy changes. The vulnerability is addressed in version 0.14.0, where enhanced access controls are implemented.

Affected Version(s)

gittuf < 0.14.0

References

CVSS V4

Score:
4.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.