---
title:

GitHub's Verified Commit Status Susceptible to Hash Chain Malleability

date: 2026-07-07
tags: [#news, #devops ]
draft: false
---

Researchers have discovered that attackers can create byte-distinct commits that share the same “Verified” status, effectively undermining the integrity of supply-chain security measurements. This vulnerability stems from signature malleability and GitHub’s lenient validation process, which assigns unique hashes to non-canonical signatures.