« Volver al listado

Go-git Project

Go-git Project Go-git: vulnerabilidades y CVE

Go-git Project Go-git tiene 11 vulnerabilidades publicadas, 7 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE11
Últimos 12 meses7
Críticas2
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-45571Media (5.4)0.33%—27 may 2026
go-git is an extensible git implementation library written in pure Go. Prior to 5.19.1 and 6.0.0-alpha.4, a path validation issue in go-git could allow crafted repository data to affect files outside the intended…
CVE-2026-45570Baja (2.3)0.43%—27 may 2026
go-git is an extensible git implementation library written in pure Go. Prior to 5.19.1 and 6.0.0-alpha.4, go-git's SSH transport constructs the remote exec command by wrapping the repository path in single quotes…
CVE-2026-45022Alta (7)0.16%—27 may 2026
go-git is an extensible git implementation library written in pure Go. Prior to 5.19.0 and 6.0.0-alpha.3, go-git may parse malformed Git objects in a way that differs from upstream Git. When commit or tag objects…
CVE-2026-41506Alta (7.4)0.26%—8 may 2026
go-git is an extensible git implementation library written in pure Go. Prior to versions 5.18.0 and 6.0.0-alpha.2, go-git may leak HTTP authentication credentials when following redirects during smart-HTTP clone and…
CVE-2026-34165Media (5)0.15%—31 mar 2026
go-git is an extensible git implementation library written in pure Go. From version 5.0.0 to before version 5.17.1, a vulnerability has been identified in which a maliciously crafted .idx file can cause asymmetric…
CVE-2026-33762Baja (2.8)0.15%—31 mar 2026
go-git is an extensible git implementation library written in pure Go. Prior to version 5.17.1, go-git’s index decoder for format version 4 fails to validate the path name prefix length before applying it to the…
CVE-2026-25934Media (4.3)0.16%—9 feb 2026
go-git is a highly extensible git implementation library written in pure Go. Prior to 5.16.5, a vulnerability was discovered in go-git whereby data integrity values for .pack and .idx files were not properly verified.…
CVE-2025-21614Alta (7.5)0.72%—6 ene 2025
go-git is a highly extensible git implementation library written in pure Go. A denial of service (DoS) vulnerability was discovered in go-git versions prior to v5.13. This vulnerability allows an attacker to perform…
CVE-2025-21613Crítica (9.2)1.3%—6 ene 2025
go-git is a highly extensible git implementation library written in pure Go. An argument injection vulnerability was discovered in go-git versions prior to v5.13. Successful exploitation of this vulnerability could…
CVE-2023-49569Crítica (9.8)1.5%—12 ene 2024
A path traversal vulnerability was discovered in go-git versions prior to v5.11. This vulnerability allows an attacker to create and amend files across the filesystem. In the worse case scenario, remote code execution…
CVE-2023-49568Alta (7.5)0.70%—12 ene 2024
A denial of service (DoS) vulnerability was discovered in go-git versions prior to v5.11. This vulnerability allows an attacker to perform denial of service attacks by providing specially crafted responses from a Git…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1203 Exploitation for Client Execution1
  2. T1210 Exploitation of Remote Services1
  3. T1552.007 Container API1
  4. T1565.002 Transmitted Data Manipulation1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.