Junglewise Threat Intelligence

CVE-2026-44544: gittuf policy rollback via Reference State Log manipulation

CVE-2026-44544 · Severity: medium · CVSS 4 · Published 2026-05-14

Vendors: Go.

Executive brief

gittuf is a security layer for Git repositories that enforces policies on code changes. A vulnerability allows an attacker with repository push access to roll back the security policy to a previous valid version. This could allow an attacker to re-enable old, less restrictive rules or restore access for users who were previously removed from the project.

Technical details

gittuf determines the active security policy by inspecting the Reference State Log (RSL). A vulnerability exists where the RSL verification process only checks if a new policy entry is signed by a threshold of current root keys, but does not verify that the policy is newer than the current one. An attacker with push access to the RSL can create an entry pointing to a previous valid policy state, effectively performing a rollback. This is possible as long as the old policy was signed by keys still trusted by the current root of trust. The fix in version 0.14.0 introduces a monotonically increasing version number in policy metadata to ensure sequential updates.

Affected products

  • gittuf gittuf <= 0.13.1

Timeline

  • 2026-05-01: disclosed: Vulnerability reported and fix developed
  • 2026-05-07: advisory
  • 2026-05-14: patched: NVD publication and final updates

References