CVE-2026-44544: gittuf's policy can be rolled back to prior valid versions
(updated )
An attacker with push access to gittuf’s Reference State Log (RSL) can roll back the current policy to any previous policy trusted by the current set of root keys.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-44544 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →