GitHub 'Verified' Commits Can Be Rewritten Into New Hashes Without Breaking Signatures
A vulnerability has been discovered in GitHub's signature verification process. Attackers can rewrite signed Git commits, creating new commits with the same content but a different hash, while still appearing as "Verified" to GitHub. This is achieved by manipulating the signature data itself, bypassing traditional hash-based checks. The flaw stems from GitHub's failure to strictly canonicalize signatures before verifying them, allowing for the creation of valid, yet misleading, commits. This doesn't break SHA-256 or hash collisions, but it undermines the uniqueness of commit hashes and can be exploited to introduce malicious code.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
