GitHub 'Verified' Commits Can Be Rewritten Into New Hashes Without Breaking Signatures

GitHub 'Verified' Commits Can Be Rewritten Into New Hashes Without Breaking Signatures

New research reveals a significant vulnerability in GitHub's commit verification system, where signed commits can be manipulated without invalidating their signatures. This means attackers can rewrite the content of verified commits while keeping the same author, date, and signature, fooling reviewers into trusting the integrity of the changes. This flaw highlights the need for more robust verification methods in software development, as it poses a serious risk to the trustworthiness of code hosted on platforms like GitHub.

Original Source

Read the full article at Thehackernews →

KhanList aggregates and links to publicly available news content. We do not host full articles from third-party sources. Always verify important information with original sources.