Go-git Project

Go-git

11 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.37%
  • Veröffentlicht 27.05.2026 15:16:30
  • Zuletzt bearbeitet 04.06.2026 18:00:39

go-git is an extensible git implementation library written in pure Go. Prior to 5.19.1 and 6.0.0-alpha.4, go-git's SSH transport constructs the remote exec command by wrapping the repository path in single quotes without escaping single quotes embedd...

  • EPSS 0.3%
  • Veröffentlicht 27.05.2026 15:16:30
  • Zuletzt bearbeitet 04.06.2026 18:01:41

go-git is an extensible git implementation library written in pure Go. Prior to 5.19.1 and 6.0.0-alpha.4, a path validation issue in go-git could allow crafted repository data to affect files outside the intended checkout target, including the reposi...

  • EPSS 0.16%
  • Veröffentlicht 27.05.2026 15:16:29
  • Zuletzt bearbeitet 04.06.2026 17:57:46

go-git is an extensible git implementation library written in pure Go. Prior to 5.19.0 and 6.0.0-alpha.3, go-git may parse malformed Git objects in a way that differs from upstream Git. When commit or tag objects contain ambiguous or malformed header...

  • EPSS 0.26%
  • Veröffentlicht 08.05.2026 13:43:19
  • Zuletzt bearbeitet 12.05.2026 14:33:02

go-git is an extensible git implementation library written in pure Go. Prior to versions 5.18.0 and 6.0.0-alpha.2, go-git may leak HTTP authentication credentials when following redirects during smart-HTTP clone and fetch operations. This issue has b...

  • EPSS 0.15%
  • Veröffentlicht 31.03.2026 13:47:42
  • Zuletzt bearbeitet 02.04.2026 16:49:29

go-git is an extensible git implementation library written in pure Go. Prior to version 5.17.1, go-git’s index decoder for format version 4 fails to validate the path name prefix length before applying it to the previously decoded path name. A malici...

  • EPSS 0.15%
  • Veröffentlicht 31.03.2026 13:46:37
  • Zuletzt bearbeitet 02.04.2026 16:49:16

go-git is an extensible git implementation library written in pure Go. From version 5.0.0 to before version 5.17.1, a vulnerability has been identified in which a maliciously crafted .idx file can cause asymmetric memory consumption, potentially exha...

  • EPSS 0.14%
  • Veröffentlicht 09.02.2026 22:13:41
  • Zuletzt bearbeitet 20.02.2026 20:21:19

go-git is a highly extensible git implementation library written in pure Go. Prior to 5.16.5, a vulnerability was discovered in go-git whereby data integrity values for .pack and .idx files were not properly verified. This resulted in go-git potentia...

  • EPSS 1.24%
  • Veröffentlicht 06.01.2025 17:15:47
  • Zuletzt bearbeitet 17.04.2025 02:33:57

go-git is a highly extensible git implementation library written in pure Go. An argument injection vulnerability was discovered in go-git versions prior to v5.13. Successful exploitation of this vulnerability could allow an attacker to set arbitrary ...

  • EPSS 0.7%
  • Veröffentlicht 06.01.2025 17:15:47
  • Zuletzt bearbeitet 30.09.2025 15:24:48

go-git is a highly extensible git implementation library written in pure Go. A denial of service (DoS) vulnerability was discovered in go-git versions prior to v5.13. This vulnerability allows an attacker to perform denial of service attacks by provi...

  • EPSS 1.52%
  • Veröffentlicht 12.01.2024 11:15:13
  • Zuletzt bearbeitet 21.11.2024 08:33:34

A path traversal vulnerability was discovered in go-git versions prior to v5.11. This vulnerability allows an attacker to create and amend files across the filesystem. In the worse case scenario, remote code execution could be achieved. Applications...