CVE-2026-45571
published 2026-05-27CVE-2026-45571: go-git is an extensible git implementation library written in pure Go. Prior to 5.19.1 and 6.0.0-alpha.4, a path validation issue in go-git could allow crafted…
PriorityP429medium5.4CVSS 3.1
AVNACLPRNUIRSUCNILAL
EPSS
0.33%
23.5th percentile
go-git is an extensible git implementation library written in pure Go. Prior to 5.19.1 and 6.0.0-alpha.4, a path validation issue in go-git could allow crafted repository data to affect files outside the intended checkout target, including the repository's .git directory. These validations were introduced in upstream Git years ago, so the vulnerability arose from go-git drifting from those checks. This vulnerability is fixed in 5.19.1 and 6.0.0-alpha.4.
Affected
34 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| github.com | go-git_go-git | 0 – 44.7.0 | — |
| github.com | go-git_go-git_v5 | >= 0 < 5.19.1 | 5.19.1 |
| github.com | go-git_go-git_v6 | >= 0 < 6.0.0-alpha.4 | 6.0.0-alpha.4 |
| go-git | go-git | < 5.19.1 | 5.19.1 |
| go-git | go-git | — | — |
| go-git_project | go-git | < 5.19.1 | 5.19.1 |
| go-git_project | go-git | — | — |
| odf4 | cephcsi-rhel9-operator_1782931768 | — | — |
| odf4 | cephcsi-rhel9_1782932114 | — | — |
| odf4 | devicefinder-rhel9_1782932104 | — | — |
| odf4 | mcg-core-rhel9_1783536000 | — | — |
| odf4 | mcg-rhel9-operator_1783535989 | — | — |
| odf4 | ocs-client-console-rhel9_1783536515 | — | — |
| odf4 | ocs-client-rhel9-operator_1782932521 | — | — |
| odf4 | ocs-metrics-exporter-rhel9_1783018461 | — | — |
| odf4 | ocs-rhel9-operator_1783018421 | — | — |
| odf4 | odf-blackbox-exporter-rhel9_1782932812 | — | — |
| odf4 | odf-cli-rhel9_1783537001 | — | — |
| odf4 | odf-cloudnative-pg-rhel9-operator_1782932919 | — | — |
| odf4 | odf-console-rhel9_1783537586 | — | — |
| odf4 | odf-cosi-sidecar-rhel9_1782932969 | — | — |
| odf4 | odf-csi-addons-rhel9-operator_1782933015 | — | — |
| odf4 | odf-csi-addons-sidecar-rhel9_1782933042 | — | — |
| odf4 | odf-drbd-rhel9_1783537392 | — | — |
| odf4 | odf-external-snapshotter-rhel9-operator_1782933235 | — | — |
CVSS provenance
nvdv3.15.4MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L
vendor_redhat5.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
go-git: Crafted repositories may modify main and submodule .git directories
ghsa·2026-05-19
CVE-2026-45571 [MEDIUM] CWE-22 go-git: Crafted repositories may modify main and submodule .git directories
go-git: Crafted repositories may modify main and submodule .git directories
### Impact
A path validation issue in `go-git` could allow crafted repository data to affect files outside the intended checkout target, including the repository's `.git` directory.
These validations were introduced in upstream Git years ago, so the vulnerability arose from go-git drifting from those checks. Some attack vectors were platform-specific: certain payloads affected only Windows users, others affected only macOS users, and some applied across all supported platforms.
Using non-descendant `go-billy` filesystem instances, or different filesystem types, for the `Storer` and `Worktree` may provide some isolation against `.git` directory manipulation. For example, users that store the `.git` directory thro
Red Hat
github.com/go-git/go-git: go-git: Path validation flaw allows unauthorized file access
vendor_redhat·2026-05-27·CVSS 5.4
CVE-2026-45571 [MEDIUM] CWE-22 github.com/go-git/go-git: go-git: Path validation flaw allows unauthorized file access
github.com/go-git/go-git: go-git: Path validation flaw allows unauthorized file access
go-git is an extensible git implementation library written in pure Go. Prior to 5.19.1 and 6.0.0-alpha.4, a path validation issue in go-git could allow crafted repository data to affect files outside the intended checkout target, including the repository's .git directory. These validations were introduced in upstream Git years ago, so the vulnerability arose from go-git drifting from those checks. This vulnerability is fixed in 5.19.1 and 6.0.0-alpha.4.
A flaw was found in go-git, a Git implementation library. This path validation vulnerability allows an attacker to use specially crafted repository data. This data can cause go-git to modify or access files outside of the intended repository checkout, i
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-45571 golang-github-git-5: go-git: Path validation flaw allows unauthorized file access [fedora-all]
bugzilla·2026-07-09·CVSS 5.4
CVE-2026-45571 [MEDIUM] CVE-2026-45571 golang-github-git-5: go-git: Path validation flaw allows unauthorized file access [fedora-all]
CVE-2026-45571 golang-github-git-5: go-git: Path validation flaw allows unauthorized file access [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
go-git is an extensible git implementation library written in pure Go. Prior to 5.19.1 and 6.0.0-alpha.4, a path validation issue in go-git could allow crafted repository data to affect files outside the intended checkout target, including the repository's .git directory. These validations were introduced in upstream Git years ago, so the vulnerability arose from go-git drifting from those checks. This vulnerability is fixed in 5.19.1 and 6.0.0-alpha.4.
Bugzilla
CVE-2026-45571 github.com/go-git/go-git: go-git: Path validation flaw allows unauthorized file access
bugzilla·2026-05-27·CVSS 5.4
CVE-2026-45571 [MEDIUM] CVE-2026-45571 github.com/go-git/go-git: go-git: Path validation flaw allows unauthorized file access
CVE-2026-45571 github.com/go-git/go-git: go-git: Path validation flaw allows unauthorized file access
go-git is an extensible git implementation library written in pure Go. Prior to 5.19.1 and 6.0.0-alpha.4, a path validation issue in go-git could allow crafted repository data to affect files outside the intended checkout target, including the repository's .git directory. These validations were introduced in upstream Git years ago, so the vulnerability arose from go-git drifting from those checks. This vulnerability is fixed in 5.19.1 and 6.0.0-alpha.4.
2026-05-27
Published