Skip to content
Noroxi

go-git project records

11 published records for vendor go-git project.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
1
With a fix record
100%
Median publish → KEV
No record has entered KEV

All records

11 records
  • Maliciously crafted Git server replies can lead to path traversal and RCE on go-git clients

    CriticalCVSS 9.8No exploitEPSS 2%

    go-git project · go-gitJan 12, 2024

  • go-git has an Argument Injection via the URL field

    CriticalCVSS 9.2No exploitEPSS 1%

    go-git project · go-gitJan 6, 2025

  • go-git clients vulnerable to DoS via maliciously crafted Git server replies

    HighCVSS 7.5No exploitEPSS 1%

    go-git project · go-gitJan 6, 2025

  • Maliciously crafted Git server replies can cause DoS on go-git clients

    HighCVSS 7.5No exploitEPSS 1%

    go-git project · go-gitJan 12, 2024

  • go-git Credential leak via cross-host redirect in smart HTTP transport

    HighCVSS 7.4No exploitEPSS 0%

    go-git project · go-gitMay 8, 2026

  • go-git: Improper parsing of specially crafted objects may lead to inconsistent interpretation compared to upstream Git

    HighCVSS 7.0No exploitEPSS 0%

    go-git project · go-gitMay 27, 2026

  • go-git: Crafted repositories may modify main and submodule .git directories

    MediumCVSS 5.4No exploitEPSS 0%

    go-git project · go-gitMay 27, 2026

  • go-git: Maliciously crafted idx file can cause asymmetric memory consumption

    MediumCVSS 5.0No exploitEPSS 0%

    go-git project · go-gitMar 31, 2026

  • go-git improperly verifies data integrity values for .idx and .pack files

    MediumCVSS 4.3No exploitEPSS 0%

    go-git project · go-gitFeb 9, 2026

  • go-git: Missing validation decoding Index v4 files leads to panic

    LowCVSS 2.8No exploitEPSS 0%

    go-git project · go-gitMar 31, 2026

  • go-git: Improper single-quote escaping in go-git SSH transport

    LowCVSS 2.3No exploitEPSS 0%

    go-git project · go-gitMay 27, 2026