logo

GitHub 'Verified' Commits Can Be Rewritten Into New Hashes Without Breaking Signatures

ID: ad877794-8688-5f81-86b4-deab344f0319

STIX ID: report--ad877794-8688-5f81-86b4-deab344f0319

Feed Name: The Hacker News

Threat Score
55/100

Date Published: 2026-07-08

Date Updated: 2026-07-18

Author: [email protected] (The Hacker News)

...
...

New research demonstrates that signature malleability permits creating re-encoded, validly signed Git commits with different hashes while GitHub still marks them "Verified". This "hash chain malleability" can subvert blocklists, deduplication, provenance logs, and other tooling that treat a verified commit hash as a unique identifier; the flaw arises from forges not canonicalizing signatures and should be fixed on the forge side.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.