---
id: CVE-2026-46728
title: >-
  Das U-Boot before 2026.04 allows FIT (Flat Image Tree) signature verification
  bypass because hashed-nodes is omitted from a hash.
summary: >-
  Das U-Boot before 2026.04 allows FIT (Flat Image Tree) signature verification
  bypass because hashed-nodes is omitted from a hash.
severity: high
cvss: 8.2
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'
cwe:
  - CWE-346
vendor: denx
product: u-boot
affected:
  - 'u-boot >= 2013.07, < 2026.04'
  - u-boot = 2026.04
patched:
  - u-boot 2026.04
published: '2026-05-16'
updated: '2026-09-11'
sourceUpdated: '2026-09-11T15:55:09.027'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-46728'
references:
  - url: 'https://github.com/barebox/barebox/security/advisories/GHSA-3fvj-q26p-j6h4'
    label: cve@mitre.org
  - url: >-
      https://github.com/u-boot/u-boot/commit/2092322b31cc8b1f8c9e2e238d1043ae0637b241
    label: cve@mitre.org
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-05-18T12:53:04.053259Z'
ingestedAt: '2026-09-14T04:34:34.739Z'
epss: 0.00212
epssPercentile: 0.1183
---

## Overview

Das U-Boot before 2026.04 allows FIT (Flat Image Tree) signature verification bypass because hashed-nodes is omitted from a hash.

## Affected

- `u-boot >= 2013.07, < 2026.04`
- `u-boot = 2026.04`

## Remediation

Upgrade past the affected range:

- `u-boot 2026.04`
