Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

go-git — Vulnerabilities & Security Advisories 13

All 13 CVE vulnerabilities found in go-git, with AI-generated Chinese analysis, references, and POCs.

Vendor: go-git

CVE IDTitleCVSSSeverityPublished
CVE-2026-71557 go-git: Malicious reference names may modify files outside the reference storage CWE-22 6.3 Medium2026-08-07
CVE-2026-71556 go-git: Worktree operations may follow symlinks CWE-59 7.1 High2026-08-07
CVE-2026-45570 go-git: Improper single-quote escaping in go-git SSH transport CWE-116--2026-05-27
CVE-2026-45571 go-git: Crafted repositories may modify main and submodule .git directories CWE-22 5.4 Medium2026-05-27
CVE-2026-45022 go-git: Improper parsing of specially crafted objects may lead to inconsistent interpretation compared to upstream Git CWE-180--2026-05-27
CVE-2026-41506 go-git Credential leak via cross-host redirect in smart HTTP transport CWE-522 4.7 Medium2026-05-08
CVE-2026-33762 go-git: Missing validation decoding Index v4 files leads to panic CWE-129 2.8 Low2026-03-31
CVE-2026-34165 go-git: Maliciously crafted idx file can cause asymmetric memory consumption CWE-191 5.0 Medium2026-03-31
CVE-2026-25934 go-git improperly verifies data integrity values for .idx and .pack files CWE-354 4.3 Medium2026-02-09
CVE-2025-21614 go-git clients vulnerable to DoS via maliciously crafted Git server replies CWE-400 7.5 High2025-01-06
CVE-2025-21613 go-git has an Argument Injection via the URL field CWE-88 9.1 -2025-01-06
CVE-2023-49569 Maliciously crafted Git server replies can lead to path traversal and RCE on go-git clients CWE-22 9.8 Critical2024-01-12
CVE-2023-49568 Maliciously crafted Git server replies can cause DoS on go-git clients CWE-20 7.5 High2024-01-12

All 13 known CVE vulnerabilities affecting go-git with full Chinese analysis, references, and POCs where available.