CVE-2026-64655CWE-185

CVE-2026-64655

published August 7, 2026

CVSS
2.1
EPSS
0%
Percentile
26.0
In the wild
Unconfirmed
What it is

GitHub CLI (gh) is GitHub’s official command line tool. Prior to 2.97.0, gh attestation verify  builds the certificate Subject Alternative Name matcher from the --signer-repo and --signer-workflow  flag values without escaping regex metacharacters, so a user-supplied repository or workflow name is treated as a regular expression rather than a literal string. Because GitHub permits characters such as  `.`  in organization, repository, and workflow path names and  `.`  is a regex wildcard, an attacker can register a lookalike name (for example github/artifact.attestations-workflows) that satisfies a matcher intended for a different trusted signer (github/artifact-attestations-workflows), bypassing the intended Sigstore attestation verification. Exploitation requires the attacker to create a plausible lookalike repository and produce valid attestations from it, which could undermine supply chain verification for CI/CD pipelines or policy gates that pin trust to a specific signing workflow. This issue is fixed in version 2.97.0.

The record
Technical detail
CVSS
2.1 · NONE
CVSS v4.0
Not supplied
EPSS
0.00333 · 26.0th percentile
Weakness
CWE-185 · Incorrect Regular Expression
Published
2026-08-07T02:18Z
References (3)
EPSS history
Timeline
  • 06 AUG 18:41Z
    GitHub CLI: Attestation Verification Bypass via Unescaped Regex Metacharacters in SAN Matching
    cvelistv5