cbcvebase.
CVE-2026-71556
published 2026-08-07

CVE-2026-71556: go-git is an extensible git implementation library written in pure Go. Prior to 5.19.2 and 6.0.0-alpha.5, worktree operations (including checkout, status, and…

PriorityP337high7.1CVSS 3.1
AVNACLPRNUIRSUCNIHAL
EPSS
0.45%
36.8th percentile
go-git is an extensible git implementation library written in pure Go. Prior to 5.19.2 and 6.0.0-alpha.5, worktree operations (including checkout, status, and add) resolve symbolic links inside the working tree without confining resolution to the worktree boundary, so a maliciously crafted repository containing a symlink can cause go-git to read from or write to files outside the intended working directory when the repository is cloned and its worktree operations are used. Versions 5.19.2 and 6.0.0-alpha.5.

Affected

10 ranges
VendorProductVersion rangeFixed in
github.comgo-git_go-git_v5>= 0 < 5.19.25.19.2
github.comgo-git_go-git_v6>= 0 < 6.0.0-alpha.56.0.0-alpha.5
go-gitgo-git< 5.19.25.19.2
go-gitgo-git——
multicluster-engineassisted-installer-controller-rhel9——
multicluster-engineassisted-service-9-rhel9——
multicluster-enginecluster-image-set-controller-rhel9——
multicluster-enginemust-gather-rhel9——
rhacm2acm-must-gather-rhel9——
rhacm2multicluster-operators-subscription-rhel9——

CVSS provenance

nvdv3.17.1HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L
vendor_redhat7.1HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.