Package impact

golang Go / github.com/go-git/go-git/v5

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Published Description Impact
CVE-2026-45022 high 8.0 19h ago go-git is an extensible git implementation library written in pure Go. Prior to 5.19.0 and 6.0.0-alpha.3, go-git may parse malformed Git objects in a way that differs from upstream Git. When commit o… debiangolang
CVE-2025-21614 high 8.0 1y ago Important: grafana security update rockylinuxdebiangolang
CVE-2025-21613 high 8.0 1y ago Important: grafana security update rockylinuxdebiansusegolang
CVE-2026-41506 high 7.4 7.4 20d ago go-git: Credential leak via cross-host redirect in smart HTTP transport debiansusegolang
CVE-2026-45571 medium 5.4 5.4 19h ago go-git is an extensible git implementation library written in pure Go. Prior to 5.19.1 and 6.0.0-alpha.4, a path validation issue in go-git could allow crafted repository data to affect files outside… debiangolang
CVE-2026-45570 low 2.5 19h ago go-git is an extensible git implementation library written in pure Go. Prior to 5.19.1 and 6.0.0-alpha.4, go-git's SSH transport constructs the remote exec command by wrapping the repository path in … debiangolang
CVE-2026-34165 unknown 2mo ago go-git is an extensible git implementation library written in pure Go. From version 5.0.0 to before version 5.17.1, a vulnerability has been identified in which a maliciously crafted .idx file can ca… debiangolang
CVE-2026-33762 unknown 2mo ago go-git is an extensible git implementation library written in pure Go. Prior to version 5.17.1, go-git’s index decoder for format version 4 fails to validate the path name prefix length before applyi… debiangolang
CVE-2026-25934 unknown 4mo ago go-git is a highly extensible git implementation library written in pure Go. Prior to 5.16.5, a vulnerability was discovered in go-git whereby data integrity values for .pack and .idx files were not … debiansusegolang
CVE-2023-49569 unknown 2y ago A path traversal vulnerability was discovered in go-git versions prior to v5.11. This vulnerability allows an attacker to create and amend files across the filesystem. In the worse case scenario, rem… debiangolang
CVE-2023-49568 unknown 2y ago A denial of service (DoS) vulnerability was discovered in go-git versions prior to v5.11. This vulnerability allows an attacker to perform denial of service attacks by providing specially crafted res… debiangolang