Github.com/go-git/go-git/v5
This hub aggregates every CVE we track for Github.com/go-git/go-git/v5, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
7
CVEs tracked
2
Critical
2
High
0
In CISA KEV
Severity distribution
HIGH2CRITICAL2MEDIUM1
Monthly trend
0
0
0
2
0
0
0
0
0
0
0
0
0
0
0
0
1
0
1
1
0
0
0
0
2024-102026-09
Latest CVEs
The 7 most recently published vulnerabilities affecting Github.com/go-git/go-git/v5.
- GHSA-w5pp-99ch-qj29go-git: Malformed Git object data may cause panics or resource exhaustion
- GHSA-3xc5-wrhm-f963go-git: Credential leak via cross-host redirect in smart HTTP transport
- CVE-2026-25934go-git improperly verifies data integrity values for .idx and .pack files4.3
- CVE-2025-21614go-git clients vulnerable to DoS via maliciously crafted Git server replies7.5
- CVE-2025-21613go-git has an Argument Injection via the URL field9.8
- CVE-2023-49569Maliciously crafted Git server replies can lead to path traversal and RCE on go-git clients9.8
- CVE-2023-49568Maliciously crafted Git server replies can cause DoS on go-git clients7.5
Product normalization is registry-driven with AI assist and human review. How it works