7.4
CVE-2026-41506
- EPSS 0.26%
- Veröffentlicht 08.05.2026 13:43:19
- Zuletzt bearbeitet 12.05.2026 14:33:02
- Quelle security-advisories@github.com
- CVE-Watchlists
- Unerledigt
go-git Credential leak via cross-host redirect in smart HTTP transport
go-git is an extensible git implementation library written in pure Go. Prior to versions 5.18.0 and 6.0.0-alpha.2, go-git may leak HTTP authentication credentials when following redirects during smart-HTTP clone and fetch operations. This issue has been patched in versions 5.18.0 and 6.0.0-alpha.2.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Go-git Project ≫ Go-git SwPlatformgo Version < 5.18.0
Go-git Project ≫ Go-git Version6.0.0 Updatealpha1 SwPlatformgo
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.26% | 0.17 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.4 | 2.8 | 4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N
|
| security-advisories@github.com | 4.7 | 2.8 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N
|
CWE-522 Insufficiently Protected Credentials
The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
https://github.com/go-git/go-git/security/advisories/GHSA-3xc5-wrhm-f963
https://github.com/go-git/go-git/releases/tag/v5.18.0
https://github.com/go-git/go-git/releases/tag/v6.0.0-alpha.2