CVE-2026-45570
- EPSS 0.37%
- Veröffentlicht 27.05.2026 15:16:30
- Zuletzt bearbeitet 04.06.2026 18:00:39
go-git is an extensible git implementation library written in pure Go. Prior to 5.19.1 and 6.0.0-alpha.4, go-git's SSH transport constructs the remote exec command by wrapping the repository path in single quotes without escaping single quotes embedd...
CVE-2026-45571
- EPSS 0.3%
- Veröffentlicht 27.05.2026 15:16:30
- Zuletzt bearbeitet 04.06.2026 18:01:41
go-git is an extensible git implementation library written in pure Go. Prior to 5.19.1 and 6.0.0-alpha.4, a path validation issue in go-git could allow crafted repository data to affect files outside the intended checkout target, including the reposi...
CVE-2026-45022
- EPSS 0.16%
- Veröffentlicht 27.05.2026 15:16:29
- Zuletzt bearbeitet 04.06.2026 17:57:46
go-git is an extensible git implementation library written in pure Go. Prior to 5.19.0 and 6.0.0-alpha.3, go-git may parse malformed Git objects in a way that differs from upstream Git. When commit or tag objects contain ambiguous or malformed header...
CVE-2026-41506
- EPSS 0.26%
- Veröffentlicht 08.05.2026 13:43:19
- Zuletzt bearbeitet 12.05.2026 14:33:02
go-git is an extensible git implementation library written in pure Go. Prior to versions 5.18.0 and 6.0.0-alpha.2, go-git may leak HTTP authentication credentials when following redirects during smart-HTTP clone and fetch operations. This issue has b...
CVE-2026-33762
- EPSS 0.15%
- Veröffentlicht 31.03.2026 13:47:42
- Zuletzt bearbeitet 02.04.2026 16:49:29
go-git is an extensible git implementation library written in pure Go. Prior to version 5.17.1, go-git’s index decoder for format version 4 fails to validate the path name prefix length before applying it to the previously decoded path name. A malici...
- EPSS 0.15%
- Veröffentlicht 31.03.2026 13:46:37
- Zuletzt bearbeitet 02.04.2026 16:49:16
go-git is an extensible git implementation library written in pure Go. From version 5.0.0 to before version 5.17.1, a vulnerability has been identified in which a maliciously crafted .idx file can cause asymmetric memory consumption, potentially exha...
CVE-2026-25934
- EPSS 0.14%
- Veröffentlicht 09.02.2026 22:13:41
- Zuletzt bearbeitet 20.02.2026 20:21:19
go-git is a highly extensible git implementation library written in pure Go. Prior to 5.16.5, a vulnerability was discovered in go-git whereby data integrity values for .pack and .idx files were not properly verified. This resulted in go-git potentia...
CVE-2025-21613
- EPSS 1.24%
- Veröffentlicht 06.01.2025 17:15:47
- Zuletzt bearbeitet 17.04.2025 02:33:57
go-git is a highly extensible git implementation library written in pure Go. An argument injection vulnerability was discovered in go-git versions prior to v5.13. Successful exploitation of this vulnerability could allow an attacker to set arbitrary ...
CVE-2025-21614
- EPSS 0.7%
- Veröffentlicht 06.01.2025 17:15:47
- Zuletzt bearbeitet 30.09.2025 15:24:48
go-git is a highly extensible git implementation library written in pure Go. A denial of service (DoS) vulnerability was discovered in go-git versions prior to v5.13. This vulnerability allows an attacker to perform denial of service attacks by provi...
CVE-2023-49569
- EPSS 1.52%
- Veröffentlicht 12.01.2024 11:15:13
- Zuletzt bearbeitet 21.11.2024 08:33:34
A path traversal vulnerability was discovered in go-git versions prior to v5.11. This vulnerability allows an attacker to create and amend files across the filesystem. In the worse case scenario, remote code execution could be achieved. Applications...