Advisory Database
  • Advisories
  • Dependency Scanning
  1. golang
  2. ›
  3. github.com/cli/cli/v2
  4. ›
  5. CVE-2026-48501

CVE-2026-48501: GitHub CLI has an incorrect authorization header in API requests to TUF repository mirrors via `gh attestation`, `gh release verify`, and `gh release verify-asset` commands

May 29, 2026 (updated June 4, 2026)

GitHub CLI incorrectly includes an authorization header in API requests to TUF repository mirrors via gh attestation, gh release verify, and gh release verify-asset commands.

Affected users:

  • Authenticated github.com users who previously ran gh attestation commands, gh release verify, or gh release verify-asset: the github.com token was included in requests to tuf-repo.github.com, a GitHub Pages domain that is not a GitHub API endpoint. All authentication types are affected.
  • Users with GH_ENTERPRISE_TOKEN or GITHUB_ENTERPRISE_TOKEN set who previously ran gh attestation commands, gh release verify, or gh release verify-asset: the enterprise token was included in requests to external hosts tuf-repo-cdn.sigstore.dev and tmaproduction.blob.core.windows.net. These hosts are not operated by GitHub.

References

  • github.com/advisories/GHSA-8xvp-7hj6-mcj9
  • github.com/cli/cli/releases/tag/v2.93.0
  • github.com/cli/cli/security/advisories/GHSA-8xvp-7hj6-mcj9
  • nvd.nist.gov/vuln/detail/CVE-2026-48501

Code Behaviors & Features

Detect and mitigate CVE-2026-48501 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 2.93.0

Fixed versions

  • 2.93.0

Solution

Upgrade to version 2.93.0 or above.

Impact 7.4 HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

Learn more about CVSS

Weakness

  • CWE-863: Incorrect Authorization

Source file

go/github.com/cli/cli/v2/CVE-2026-48501.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Sat, 06 Jun 2026 00:17:58 +0000.