Vendorsgo-git Projectgo-gitall versions
Vulnerabilities

go-git Project go-git

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

11CVEs
CVE-2023-49569
Maliciously crafted Git server replies can lead to path traversal and RCE on go-git clients
Published 2024-01-12 · Modified
9.8EPSS 0.015
CVE-2025-21613
go-git has an Argument Injection via the URL field
Published 2025-01-06 · Analyzed
9.8EPSS 0.013
CVE-2026-45570
go-git: Improper single-quote escaping in go-git SSH transport
Published 2026-05-27 · Analyzed
9.6EPSS 0.004
CVE-2025-21614
go-git clients vulnerable to DoS via maliciously crafted Git server replies
Published 2025-01-06 · Analyzed
7.5EPSS 0.007
CVE-2023-49568
Maliciously crafted Git server replies can cause DoS on go-git clients
Published 2024-01-12 · Modified
7.5EPSS 0.007
CVE-2026-45022
go-git: Improper parsing of specially crafted objects may lead to inconsistent interpretation compared to upstream Git
Published 2026-05-27 · Analyzed
7.5EPSS 0.002
CVE-2026-41506
go-git Credential leak via cross-host redirect in smart HTTP transport
Published 2026-05-08 · Analyzed
7.4EPSS 0.005
CVE-2026-45571
go-git: Crafted repositories may modify main and submodule .git directories
Published 2026-05-27 · Analyzed
5.4EPSS 0.003
CVE-2026-34165
go-git: Maliciously crafted idx file can cause asymmetric memory consumption
Published 2026-03-31 · Analyzed
5.0EPSS 0.001
CVE-2026-25934
go-git improperly verifies data integrity values for .idx and .pack files
Published 2026-02-09 · Analyzed
4.3EPSS 0.002
CVE-2026-33762
go-git: Missing validation decoding Index v4 files leads to panic
Published 2026-03-31 · Analyzed
2.8EPSS 0.002