cbcvebase.
CVE-2026-71557
published 2026-08-07

CVE-2026-71557: go-git is an extensible git implementation library written in pure Go. Prior to 5.19.2 and 6.0.0-alpha.5, reference names are not sanitized before being used…

PriorityP337medium6.3CVSS 3.1
AVNACLPRLUIRSUCNIHAL
EPSS
0.41%
35.2th percentile
go-git is an extensible git implementation library written in pure Go. Prior to 5.19.2 and 6.0.0-alpha.5, reference names are not sanitized before being used to construct on-disk paths under the reference storage directory, so a maliciously crafted reference name (for example containing directory-traversal sequences) can cause go-git to write files outside the intended reference storage directory. Versions 5.19.2 and 6.0.0-alpha.5 fix the issue.

Affected

4 ranges
VendorProductVersion rangeFixed in
github.comgo-git_go-git_v5>= 0 < 5.19.25.19.2
github.comgo-git_go-git_v6>= 0 < 6.0.0-alpha.56.0.0-alpha.5
go-gitgo-git< 5.19.25.19.2
go-gitgo-git——
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.