« Back to list

Go-git Project

Go-git Project Go-git: vulnerabilities and CVEs

Go-git Project Go-git has 11 published vulnerabilities, 7 of them in the last 12 months. 2 are rated critical and 0 are listed by CISA as actively exploited.

CVEs11
Last 12 months7
Critical2
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-45571Medium (5.4)0.33%—May 27, 2026
go-git is an extensible git implementation library written in pure Go. Prior to 5.19.1 and 6.0.0-alpha.4, a path validation issue in go-git could allow crafted repository data to affect files outside the intended…
CVE-2026-45570Low (2.3)0.43%—May 27, 2026
go-git is an extensible git implementation library written in pure Go. Prior to 5.19.1 and 6.0.0-alpha.4, go-git's SSH transport constructs the remote exec command by wrapping the repository path in single quotes…
CVE-2026-45022High (7)0.16%—May 27, 2026
go-git is an extensible git implementation library written in pure Go. Prior to 5.19.0 and 6.0.0-alpha.3, go-git may parse malformed Git objects in a way that differs from upstream Git. When commit or tag objects…
CVE-2026-41506High (7.4)0.26%—May 8, 2026
go-git is an extensible git implementation library written in pure Go. Prior to versions 5.18.0 and 6.0.0-alpha.2, go-git may leak HTTP authentication credentials when following redirects during smart-HTTP clone and…
CVE-2026-34165Medium (5)0.15%—Mar 31, 2026
go-git is an extensible git implementation library written in pure Go. From version 5.0.0 to before version 5.17.1, a vulnerability has been identified in which a maliciously crafted .idx file can cause asymmetric…
CVE-2026-33762Low (2.8)0.15%—Mar 31, 2026
go-git is an extensible git implementation library written in pure Go. Prior to version 5.17.1, go-git’s index decoder for format version 4 fails to validate the path name prefix length before applying it to the…
CVE-2026-25934Medium (4.3)0.16%—Feb 9, 2026
go-git is a highly extensible git implementation library written in pure Go. Prior to 5.16.5, a vulnerability was discovered in go-git whereby data integrity values for .pack and .idx files were not properly verified.…
CVE-2025-21614High (7.5)0.72%—Jan 6, 2025
go-git is a highly extensible git implementation library written in pure Go. A denial of service (DoS) vulnerability was discovered in go-git versions prior to v5.13. This vulnerability allows an attacker to perform…
CVE-2025-21613Critical (9.2)1.3%—Jan 6, 2025
go-git is a highly extensible git implementation library written in pure Go. An argument injection vulnerability was discovered in go-git versions prior to v5.13. Successful exploitation of this vulnerability could…
CVE-2023-49569Critical (9.8)1.5%—Jan 12, 2024
A path traversal vulnerability was discovered in go-git versions prior to v5.11. This vulnerability allows an attacker to create and amend files across the filesystem. In the worse case scenario, remote code execution…
CVE-2023-49568High (7.5)0.70%—Jan 12, 2024
A denial of service (DoS) vulnerability was discovered in go-git versions prior to v5.11. This vulnerability allows an attacker to perform denial of service attacks by providing specially crafted responses from a Git…

🎯 How it gets exploited (ATT&CK techniques)

  1. T1203 Exploitation for Client Execution1
  2. T1210 Exploitation of Remote Services1
  3. T1552.007 Container API1
  4. T1565.002 Transmitted Data Manipulation1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.