Vulnerabilities
Summary — last 7 days
New vulnerabilities2,739▲ 36 vs. last week
Critical / high1,474▲ 366 vs. last week
New active exploitation (KEV)7▼ 3 vs. last week
Unscored (no CVSS)62▼ 464 vs. last week
15 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Awaiting Analysis | Medium (6.3) | 0.41% | — | Go-gitAI | 8/7/2026 | 9/10/2026 | go-git is an extensible git implementation library written in pure Go. Prior to 5.19.2 and 6.0.0-alpha.5, reference names are not sanitized before being used to construct on-disk paths under the reference storage directory, so a maliciously crafted reference name (for example containing directory-traversal sequences)… | |
| Awaiting Analysis | High (7.1) | 0.36% | — | Go-gitAI | 8/7/2026 | 9/10/2026 | go-git is an extensible git implementation library written in pure Go. Prior to 5.19.2 and 6.0.0-alpha.5, worktree operations (including checkout, status, and add) resolve symbolic links inside the working tree without confining resolution to the worktree boundary, so a maliciously crafted repository containing a… | |
| Analyzed | Medium (5.4) | 0.33% | — | Go-git Project Go-git | 5/27/2026 | 6/17/2026 | go-git is an extensible git implementation library written in pure Go. Prior to 5.19.1 and 6.0.0-alpha.4, a path validation issue in go-git could allow crafted repository data to affect files outside the intended checkout target, including the repository's .git directory. These validations were introduced in upstream… | |
| Analyzed | Low (2.3) | 0.43% | — | Go-git Project Go-git | 5/27/2026 | 6/17/2026 | go-git is an extensible git implementation library written in pure Go. Prior to 5.19.1 and 6.0.0-alpha.4, go-git's SSH transport constructs the remote exec command by wrapping the repository path in single quotes without escaping single quotes embedded inside the path. A repository path containing a single quote can… | |
| Analyzed | High (7) | 0.16% | — | Go-git Project Go-git | 5/27/2026 | 6/17/2026 | go-git is an extensible git implementation library written in pure Go. Prior to 5.19.0 and 6.0.0-alpha.3, go-git may parse malformed Git objects in a way that differs from upstream Git. When commit or tag objects contain ambiguous or malformed headers, go-git’s decoded representation may expose values differently from… | |
| Deferred | Medium (5.3) | 0.16% | — | Go-gitAISigstore GitsignAI | 5/15/2026 | 6/17/2026 | Gitsign is a keyless Sigstore to signing tool for Git commits with your a GitHub / OIDC identity. Prior to 0.16.0, gitsign verify and gitsign verify-tag re-encode commit/tag objects through go-git's EncodeWithoutSignature before checking the signature, instead of verifying against the raw git object bytes. For… | |
| Analyzed | High (7.4) | 0.26% | — | Go-git Project Go-git | 5/8/2026 | 6/17/2026 | go-git is an extensible git implementation library written in pure Go. Prior to versions 5.18.0 and 6.0.0-alpha.2, go-git may leak HTTP authentication credentials when following redirects during smart-HTTP clone and fetch operations. This issue has been patched in versions 5.18.0 and 6.0.0-alpha.2. | |
| Analyzed | Medium (5) | 0.15% | — | Go-git Project Go-git | 3/31/2026 | 7/24/2026 | go-git is an extensible git implementation library written in pure Go. From version 5.0.0 to before version 5.17.1, a vulnerability has been identified in which a maliciously crafted .idx file can cause asymmetric memory consumption, potentially exhausting available memory and resulting in a denial-of-service (DoS)… | |
| Analyzed | Low (2.8) | 0.15% | — | Go-git Project Go-git | 3/31/2026 | 7/24/2026 | go-git is an extensible git implementation library written in pure Go. Prior to version 5.17.1, go-git’s index decoder for format version 4 fails to validate the path name prefix length before applying it to the previously decoded path name. A maliciously crafted index file can trigger an out-of-bounds slice… | |
| Analyzed | Medium (4.3) | 0.16% | — | Go-git Project Go-git | 2/9/2026 | 6/17/2026 | go-git is a highly extensible git implementation library written in pure Go. Prior to 5.16.5, a vulnerability was discovered in go-git whereby data integrity values for .pack and .idx files were not properly verified. This resulted in go-git potentially consuming corrupted files, which would likely result in… | |
| Analyzed | High (7.5) | 0.72% | — | Go-git Project Go-git | 1/6/2025 | 6/17/2026 | go-git is a highly extensible git implementation library written in pure Go. A denial of service (DoS) vulnerability was discovered in go-git versions prior to v5.13. This vulnerability allows an attacker to perform denial of service attacks by providing specially crafted responses from a Git server which triggers… | |
| Analyzed | Critical (9.2) | 1.3% | — | Go-git Project Go-git | 1/6/2025 | 6/17/2026 | go-git is a highly extensible git implementation library written in pure Go. An argument injection vulnerability was discovered in go-git versions prior to v5.13. Successful exploitation of this vulnerability could allow an attacker to set arbitrary values to git-upload-pack flags. This only happens when the file… | |
| Deferred | Medium (5.7) | 0.46% | — | Go-gitAILfprojects MinderAI | 6/18/2024 | 6/17/2026 | Minder is an open source Software Supply Chain Security Platform. Minder's Git provider is vulnerable to a denial of service from a maliciously configured GitHub repository. The Git provider clones users repositories using the `github.com/go-git/go-git/v5` library on lines `L55-L89`. The Git provider does the… | |
| Modified | Critical (9.8) | 1.5% | — | Go-git Project Go-git | 1/12/2024 | 6/17/2026 | A path traversal vulnerability was discovered in go-git versions prior to v5.11. This vulnerability allows an attacker to create and amend files across the filesystem. In the worse case scenario, remote code execution could be achieved. Applications are only affected if they are using the ChrootOS… | |
| Modified | High (7.5) | 0.70% | — | Go-git Project Go-git | 1/12/2024 | 6/17/2026 | A denial of service (DoS) vulnerability was discovered in go-git versions prior to v5.11. This vulnerability allows an attacker to perform denial of service attacks by providing specially crafted responses from a Git server which triggers resource exhaustion in go-git clients. Applications using only the in-memory… |