Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-41506

Опубликовано: 08 мая 2026
Источник: nvd
CVSS3: 4.7
CVSS3: 7.4
EPSS Низкий

Описание

go-git is an extensible git implementation library written in pure Go. Prior to versions 5.18.0 and 6.0.0-alpha.2, go-git may leak HTTP authentication credentials when following redirects during smart-HTTP clone and fetch operations. This issue has been patched in versions 5.18.0 and 6.0.0-alpha.2.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:go-git_project:go-git:*:*:*:*:*:go:*:*
Версия до 5.18.0 (исключая)
cpe:2.3:a:go-git_project:go-git:6.0.0:alpha1:*:*:*:go:*:*

EPSS

Процентиль: 18%
0.00259
Низкий

4.7 Medium

CVSS3

7.4 High

CVSS3

Дефекты

CWE-522

Связанные уязвимости

CVSS3: 4.7
ubuntu
3 месяца назад

go-git is an extensible git implementation library written in pure Go. Prior to versions 5.18.0 and 6.0.0-alpha.2, go-git may leak HTTP authentication credentials when following redirects during smart-HTTP clone and fetch operations. This issue has been patched in versions 5.18.0 and 6.0.0-alpha.2.

CVSS3: 6.5
redhat
3 месяца назад

go-git is an extensible git implementation library written in pure Go. Prior to versions 5.18.0 and 6.0.0-alpha.2, go-git may leak HTTP authentication credentials when following redirects during smart-HTTP clone and fetch operations. This issue has been patched in versions 5.18.0 and 6.0.0-alpha.2.

CVSS3: 4.7
debian
3 месяца назад

go-git is an extensible git implementation library written in pure Go. ...

suse-cvrf
3 месяца назад

Security update for trivy

CVSS3: 7.4
redos
22 дня назад

Уязвимость portainer-ce

EPSS

Процентиль: 18%
0.00259
Низкий

4.7 Medium

CVSS3

7.4 High

CVSS3

Дефекты

CWE-522