Search CVE reports


Toggle filters

1 – 7 of 7 results


CVE-2026-34165

Medium priority
Needs evaluation

go-git is an extensible git implementation library written in pure Go. From version 5.0.0 to before version 5.17.1, a vulnerability has been identified in which a maliciously crafted .idx file can cause asymmetric...

1 affected package

golang-github-go-git-go-git

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-github-go-git-go-git Needs evaluation Needs evaluation
Show less packages

CVE-2026-33762

Medium priority
Needs evaluation

go-git is an extensible git implementation library written in pure Go. Prior to version 5.17.1, go-git’s index decoder for format version 4 fails to validate the path name prefix length before applying it to the previously decoded...

1 affected package

golang-github-go-git-go-git

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-github-go-git-go-git Needs evaluation Needs evaluation
Show less packages

CVE-2026-25934

Medium priority

Some fixes available 2 of 3

go-git is a highly extensible git implementation library written in pure Go. Prior to 5.16.5, a vulnerability was discovered in go-git whereby data integrity values for .pack and .idx files were not properly verified....

1 affected package

golang-github-go-git-go-git

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-github-go-git-go-git Fixed Fixed
Show less packages

CVE-2025-21614

Medium priority

Some fixes available 2 of 4

go-git is a highly extensible git implementation library written in pure Go. A denial of service (DoS) vulnerability was discovered in go-git versions prior to v5.13. This vulnerability allows an attacker to perform denial of...

1 affected package

golang-github-go-git-go-git

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-github-go-git-go-git Fixed Fixed Not in release
Show less packages

CVE-2025-21613

Medium priority

Some fixes available 2 of 4

go-git is a highly extensible git implementation library written in pure Go. An argument injection vulnerability was discovered in go-git versions prior to v5.13. Successful exploitation of this vulnerability could allow an...

1 affected package

golang-github-go-git-go-git

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-github-go-git-go-git Fixed Fixed Not in release
Show less packages

CVE-2023-49569

Medium priority

Some fixes available 2 of 6

A path traversal vulnerability was discovered in go-git versions prior to v5.11. This vulnerability allows an attacker to create and amend files across the filesystem. In the worse case scenario, remote code execution could be...

1 affected package

golang-github-go-git-go-git

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-github-go-git-go-git Fixed Fixed Not in release Ignored
Show less packages

CVE-2023-49568

Medium priority

Some fixes available 2 of 6

A denial of service (DoS) vulnerability was discovered in go-git versions prior to v5.11. This vulnerability allows an attacker to perform denial of service attacks by providing specially crafted responses from a Git server which...

1 affected package

golang-github-go-git-go-git

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-github-go-git-go-git Fixed Fixed Not in release Ignored
Show less packages