CVE Explorer
CVE-2026-44544
gittuf is a platform-agnostic Git security system. Prior to 0.14.0, an attacker with push access to gittuf's Reference State Log (RSL) can roll back the current policy to any previous policy trusted by the current set of root keys. gittuf determines the policy to load by inspecting the RSL. Except for the very first policy (which is automatically trusted given gittuf's TOFU model, or verified against manually specified keys), whenever an RSL entry that points to a new policy is encountered, gitt
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"gittuf","vendor":"gittuf","versions":[{"status":"affected","version":"< 0.14.0"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:85388026ff14af35bae60cbc684fa28fa142ce778ce85bb5569ff6bf4f314882 · sha256:7087f587b31cdbf1… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"HIGH","attackRequirements":"PRESENT","attackVector":"NETWORK","baseScore":4.9,"baseSeverity":"MEDIUM","privilegesRequired":"LOW","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"HIGH","userInteraction":"NONE","vectorString":"CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:H/SA:N","version":"4.0","vulnAvailabilityImpact":"NONE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"NONE"},"metric_type":"cvssV4_0"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:85388026ff14af35bae60cbc684fa28fa142ce778ce85bb5569ff6bf4f314882 · sha256:7087f587b31cdbf1… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-639","description":"CWE-639: Authorization Bypass Through User-Controlled Key","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:85388026ff14af35bae60cbc684fa28fa142ce778ce85bb5569ff6bf4f314882 · sha256:7087f587b31cdbf1… · /containers/cna/problemTypes/0/descriptions/0
Source references
2 source assertions{"name":"https://github.com/gittuf/gittuf/commit/dd76efa505f9137a4a9a625c5ac67b333365a1b8","tags":["x_refsource_MISC"],"url":"https://github.com/gittuf/gittuf/commit/dd76efa505f9137a4a9a625c5ac67b333365a1b8"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:85388026ff14af35bae60cbc684fa28fa142ce778ce85bb5569ff6bf4f314882 · sha256:7087f587b31cdbf1… · /containers/cna/references/1
{"name":"https://github.com/gittuf/gittuf/security/advisories/GHSA-vxvc-cg7j-rwqj","tags":["x_refsource_CONFIRM"],"url":"https://github.com/gittuf/gittuf/security/advisories/GHSA-vxvc-cg7j-rwqj"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:85388026ff14af35bae60cbc684fa28fa142ce778ce85bb5569ff6bf4f314882 · sha256:7087f587b31cdbf1… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.