← Back to feed
Vulnerabilities & PatchesEmerging1 sourceAug 14, 2026 · 16:35via CVEFeed

CVE-2026-47191 - kas checks out SHA-like git branches as valid commits

Brief

CVE ID : CVE-2026-47191

Published : Aug. 14, 2026, 4:35 p. m.

  • 30 minutes ago

Description : kas is a setup tool for bitbake based projects. Prior to version 5. 3, when relying solely on a git commit ID (SHA-1 or SHA-256) to qualify if a checkout of a repository is equivalent to the state validated while adding its commit ID to a kas configuration, users may be tricked to check out a branch of the same name from this repository.

This implies that the referenced repository has been taken over by an attacker and modified to carry such a branch. SHA-1 commits may also be replaced by creating hash collisions, so the primary impact of this issue is on SHA-256 commit IDs. Version 5. 3 fixes the issue.

As a workaround, avoid relying solely on the commit ID for integrity validation of a repository that might become under control of a malicious 3rd party.

Read more on CVEFeed