Package impact
Go / github.com/go-git/go-git/v6
| CVE | Severity | CVSS | Risk | Flags | OS | Vendor | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-45022 | high | — | 8.0 | 1d ago | go-git is an extensible git implementation library written in pure Go. Prior to 5.19.0 and 6.0.0-alpha.3, go-git may parse malformed Git objects in a way that differs from upstream Git. When commit o… | |||
| CVE-2026-41506 | high | 7.4 | 7.4 | 20d ago | go-git: Credential leak via cross-host redirect in smart HTTP transport | |||
| CVE-2026-45571 | medium | 5.4 | 5.4 | 1d ago | go-git is an extensible git implementation library written in pure Go. Prior to 5.19.1 and 6.0.0-alpha.4, a path validation issue in go-git could allow crafted repository data to affect files outside… | |||
| CVE-2026-45570 | low | — | 2.5 | 1d ago | go-git is an extensible git implementation library written in pure Go. Prior to 5.19.1 and 6.0.0-alpha.4, go-git's SSH transport constructs the remote exec command by wrapping the repository path in … |