go-git project records
11 published records for vendor go-git project.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-129 Improper Validation of Array Index1
- CWE-180 Incorrect Behavior Order: Validate Before Canonicalize1
- CWE-191 Integer Underflow (Wrap or Wraparound)1
- CWE-20 Improper Input Validation1
- CWE-354 Improper Validation of Integrity Check Value1
The weakness classes this vendor ships most often: where to look.
CWEAll records
11 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2023-49569No exploit | Maliciously crafted Git server replies can lead to path traversal and RCE on go-git clientsgo-git project · go-git · CWE-22 | Critical9.8 | — | 1.5% | Jan 12, 2024 |
36Monitor | CVE-2025-21613No exploit | go-git has an Argument Injection via the URL fieldgo-git project · go-git · CWE-88 | Critical9.2 | — | 1.3% | Jan 6, 2025 |
30Monitor | CVE-2025-21614No exploit | go-git clients vulnerable to DoS via maliciously crafted Git server repliesgo-git project · go-git · CWE-400 | High7.5 | — | 0.7% | Jan 6, 2025 |
30Monitor | CVE-2023-49568No exploit | Maliciously crafted Git server replies can cause DoS on go-git clientsgo-git project · go-git · CWE-20 | High7.5 | — | 0.7% | Jan 12, 2024 |
29Monitor | CVE-2026-41506No exploit | go-git Credential leak via cross-host redirect in smart HTTP transportgo-git project · go-git · CWE-522 | High7.4 | — | 0.3% | May 8, 2026 |
28Monitor | CVE-2026-45022No exploit | go-git: Improper parsing of specially crafted objects may lead to inconsistent interpretation compared to upstream Gitgo-git project · go-git · CWE-180 | High7.0 | — | 0.2% | May 27, 2026 |
21Monitor | CVE-2026-45571No exploit | go-git: Crafted repositories may modify main and submodule .git directoriesgo-git project · go-git · CWE-22 | Medium5.4 | — | 0.3% | May 27, 2026 |
20Monitor | CVE-2026-34165No exploit | go-git: Maliciously crafted idx file can cause asymmetric memory consumptiongo-git project · go-git · CWE-191 | Medium5.0 | — | 0.1% | Mar 31, 2026 |
17Monitor | CVE-2026-25934No exploit | go-git improperly verifies data integrity values for .idx and .pack filesgo-git project · go-git · CWE-354 | Medium4.3 | — | 0.2% | Feb 9, 2026 |
11Monitor | CVE-2026-33762No exploit | go-git: Missing validation decoding Index v4 files leads to panicgo-git project · go-git · CWE-129 | Low2.8 | — | 0.2% | Mar 31, 2026 |
9Monitor | CVE-2026-45570No exploit | go-git: Improper single-quote escaping in go-git SSH transportgo-git project · go-git · CWE-116 | Low2.3 | — | 0.4% | May 27, 2026 |
- CVE-2023-4956939Monitor
Maliciously crafted Git server replies can lead to path traversal and RCE on go-git clients
CriticalCVSS 9.8No exploitEPSS 2%go-git project · go-gitJan 12, 2024
- CVE-2025-2161336Monitor
go-git has an Argument Injection via the URL field
CriticalCVSS 9.2No exploitEPSS 1%go-git project · go-gitJan 6, 2025
- CVE-2025-2161430Monitor
go-git clients vulnerable to DoS via maliciously crafted Git server replies
HighCVSS 7.5No exploitEPSS 1%go-git project · go-gitJan 6, 2025
- CVE-2023-4956830Monitor
Maliciously crafted Git server replies can cause DoS on go-git clients
HighCVSS 7.5No exploitEPSS 1%go-git project · go-gitJan 12, 2024
- CVE-2026-4150629Monitor
go-git Credential leak via cross-host redirect in smart HTTP transport
HighCVSS 7.4No exploitEPSS 0%go-git project · go-gitMay 8, 2026
- CVE-2026-4502228Monitor
go-git: Improper parsing of specially crafted objects may lead to inconsistent interpretation compared to upstream Git
HighCVSS 7.0No exploitEPSS 0%go-git project · go-gitMay 27, 2026
- CVE-2026-4557121Monitor
go-git: Crafted repositories may modify main and submodule .git directories
MediumCVSS 5.4No exploitEPSS 0%go-git project · go-gitMay 27, 2026
- CVE-2026-3416520Monitor
go-git: Maliciously crafted idx file can cause asymmetric memory consumption
MediumCVSS 5.0No exploitEPSS 0%go-git project · go-gitMar 31, 2026
- CVE-2026-2593417Monitor
go-git improperly verifies data integrity values for .idx and .pack files
MediumCVSS 4.3No exploitEPSS 0%go-git project · go-gitFeb 9, 2026
- CVE-2026-3376211Monitor
go-git: Missing validation decoding Index v4 files leads to panic
LowCVSS 2.8No exploitEPSS 0%go-git project · go-gitMar 31, 2026
- CVE-2026-455709Monitor
go-git: Improper single-quote escaping in go-git SSH transport
LowCVSS 2.3No exploitEPSS 0%go-git project · go-gitMay 27, 2026