Improper Handling of Case Sensitivity in GitHub CLI - #VU152994
Published: September 30, 2026
Vulnerability details
The vulnerability allows a remote user to cause an authorization policy to accept an artifact built from an unintended branch.
The vulnerability exists due to improper handling of case sensitivity in the `gh attestation verify` source-ref policy check when comparing a supplied `--source-ref` value with the source ref in a signing certificate. A remote user can create a branch whose name differs only in case from a protected branch and build an artifact from it to cause an authorization policy to accept an artifact built from an unintended branch.
The signature and certificate remain valid and accurately record the originating ref; the defect occurs in the policy check after signature verification succeeds.