CVE-2026-71557
published 2026-08-07CVE-2026-71557: go-git is an extensible git implementation library written in pure Go. Prior to 5.19.2 and 6.0.0-alpha.5, reference names are not sanitized before being used…
PriorityP337medium6.3CVSS 3.1
AVNACLPRLUIRSUCNIHAL
EPSS
0.41%
35.2th percentile
go-git is an extensible git implementation library written in pure Go. Prior to 5.19.2 and 6.0.0-alpha.5, reference names are not sanitized before being used to construct on-disk paths under the reference storage directory, so a maliciously crafted reference name (for example containing directory-traversal sequences) can cause go-git to write files outside the intended reference storage directory. Versions 5.19.2 and 6.0.0-alpha.5 fix the issue.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| github.com | go-git_go-git_v5 | >= 0 < 5.19.2 | 5.19.2 |
| github.com | go-git_go-git_v6 | >= 0 < 6.0.0-alpha.5 | 6.0.0-alpha.5 |
| go-git | go-git | < 5.19.2 | 5.19.2 |
| go-git | go-git | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
go-git: Malicious reference names may modify files outside the reference storage
ghsa·2026-08-07
CVE-2026-71557 [MEDIUM] CWE-22 go-git: Malicious reference names may modify files outside the reference storage
go-git: Malicious reference names may modify files outside the reference storage
### Impact
A path traversal issue in `go-git` could allow malicious reference names to access files outside the repository's intended reference storage.
Loose references are stored under `.git/`. The reference name was previously used as a path without verifying that the resolved path remained within the reference storage. A name such as `refs/heads/../../config` could therefore resolve to unrelated repository metadata such as `.git/config` or `.git/HEAD`.
A malicious Git server could advertise such a reference name. The name may also survive refspec mapping; for example, it could be mapped to `refs/remotes/origin/../../config` during a clone or fetch operation.
This vulnerability affects filesystem-backed
VulDB
go-git up to 5.19.1/6.0.0-alpha.4 Reference Name Sanitization path traversal
vuldb·2026-08-07·CVSS 6.3
CVE-2026-71557 [MEDIUM] go-git up to 5.19.1/6.0.0-alpha.4 Reference Name Sanitization path traversal
A vulnerability was found in go-git up to 5.19.1/6.0.0-alpha.4. It has been classified as problematic. This vulnerability affects unknown code of the component Reference Name Sanitization. This manipulation causes path traversal.
The identification of this vulnerability is CVE-2026-71557. It is possible to initiate the attack remotely. There is no exploit available.
Upgrading the affected component is recommended.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/go-git/go-git/commit/4a0e66d555de5f9a30c31e2df64f445f42bd01e7https://github.com/go-git/go-git/commit/da9f7d8a0e98b475600177348d6ece384a370f36https://github.com/go-git/go-git/pull/2247https://github.com/go-git/go-git/pull/2254https://github.com/go-git/go-git/releases/tag/v5.19.2https://github.com/go-git/go-git/releases/tag/v6.0.0-alpha.5https://github.com/go-git/go-git/security/advisories/GHSA-qgq7-7hm3-q39j
2026-08-07
Published