CVE-2026-33762
- EPSS 0.01%
- Veröffentlicht 31.03.2026 13:47:42
- Zuletzt bearbeitet 02.04.2026 16:49:29
go-git is an extensible git implementation library written in pure Go. Prior to version 5.17.1, go-git’s index decoder for format version 4 fails to validate the path name prefix length before applying it to the previously decoded path name. A malici...
- EPSS 0.01%
- Veröffentlicht 31.03.2026 13:46:37
- Zuletzt bearbeitet 02.04.2026 16:49:16
go-git is an extensible git implementation library written in pure Go. From version 5.0.0 to before version 5.17.1, a vulnerability has been identified in which a maliciously crafted .idx file can cause asymmetric memory consumption, potentially exha...
CVE-2026-25934
- EPSS 0.01%
- Veröffentlicht 09.02.2026 22:13:41
- Zuletzt bearbeitet 20.02.2026 20:21:19
go-git is a highly extensible git implementation library written in pure Go. Prior to 5.16.5, a vulnerability was discovered in go-git whereby data integrity values for .pack and .idx files were not properly verified. This resulted in go-git potentia...
CVE-2025-21613
- EPSS 2.86%
- Veröffentlicht 06.01.2025 17:15:47
- Zuletzt bearbeitet 17.04.2025 02:33:57
go-git is a highly extensible git implementation library written in pure Go. An argument injection vulnerability was discovered in go-git versions prior to v5.13. Successful exploitation of this vulnerability could allow an attacker to set arbitrary ...
CVE-2025-21614
- EPSS 0.22%
- Veröffentlicht 06.01.2025 17:15:47
- Zuletzt bearbeitet 30.09.2025 15:24:48
go-git is a highly extensible git implementation library written in pure Go. A denial of service (DoS) vulnerability was discovered in go-git versions prior to v5.13. This vulnerability allows an attacker to perform denial of service attacks by provi...
CVE-2023-49569
- EPSS 4.03%
- Veröffentlicht 12.01.2024 11:15:13
- Zuletzt bearbeitet 21.11.2024 08:33:34
A path traversal vulnerability was discovered in go-git versions prior to v5.11. This vulnerability allows an attacker to create and amend files across the filesystem. In the worse case scenario, remote code execution could be achieved. Applications...
CVE-2023-49568
- EPSS 0.11%
- Veröffentlicht 12.01.2024 11:15:12
- Zuletzt bearbeitet 21.11.2024 08:33:34
A denial of service (DoS) vulnerability was discovered in go-git versions prior to v5.11. This vulnerability allows an attacker to perform denial of service attacks by providing specially crafted responses from a Git server which triggers resource ex...