GitHub 'Verified' Commits Can Be Rewritten Into New Hashes Without Breaking Signatures
ID: ad877794-8688-5f81-86b4-deab344f0319
STIX ID: report--ad877794-8688-5f81-86b4-deab344f0319
Feed Name: The Hacker News
Threat Score
New research demonstrates that signature malleability permits creating re-encoded, validly signed Git commits with different hashes while GitHub still marks them "Verified". This "hash chain malleability" can subvert blocklists, deduplication, provenance logs, and other tooling that treat a verified commit hash as a unique identifier; the flaw arises from forges not canonicalizing signatures and should be fixed on the forge side.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
