Git Security System Vulnerability in Gittuf Affects Push Access Control
CVE-2026-44544
4.9MEDIUM
What is CVE-2026-44544?
The Gittuf platform-agnostic Git security system has a vulnerability that allows an attacker with push access to the Reference State Log (RSL) to manipulate the policy management of the system. By exploiting this flaw, the attacker can roll back the current security policy to any prior state that is still trusted by the existing root keys. This exploitation occurs when the system validates RSL entries without adequately safeguarding against unauthorized policy changes. The vulnerability is addressed in version 0.14.0, where enhanced access controls are implemented.
Affected Version(s)
gittuf < 0.14.0
