Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2026-71557

Опубликовано: 07 авг. 2026
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 6.3

Описание

go-git is an extensible git implementation library written in pure Go. Prior to 5.19.2 and 6.0.0-alpha.5, reference names are not sanitized before being used to construct on-disk paths under the reference storage directory, so a maliciously crafted reference name (for example containing directory-traversal sequences) can cause go-git to write files outside the intended reference storage directory. Versions 5.19.2 and 6.0.0-alpha.5 fix the issue.

РелизСтатусПримечание
devel

needs-triage

esm-apps/jammy

needs-triage

esm-apps/noble

needs-triage

esm-apps/resolute

needs-triage

jammy

needs-triage

noble

needs-triage

resolute

needs-triage

upstream

needs-triage

Показывать по

РелизСтатусПримечание
devel

needs-triage

jammy

DNE

noble

DNE

resolute

DNE

upstream

needs-triage

Показывать по

EPSS

Процентиль: 34%
0.00413
Низкий

6.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.3
nvd
24 дня назад

go-git is an extensible git implementation library written in pure Go. Prior to 5.19.2 and 6.0.0-alpha.5, reference names are not sanitized before being used to construct on-disk paths under the reference storage directory, so a maliciously crafted reference name (for example containing directory-traversal sequences) can cause go-git to write files outside the intended reference storage directory. Versions 5.19.2 and 6.0.0-alpha.5 fix the issue.

CVSS3: 6.3
msrc
20 дней назад

go-git: Malicious reference names may modify files outside the reference storage

CVSS3: 6.3
debian
24 дня назад

go-git is an extensible git implementation library written in pure Go. ...

CVSS3: 6.3
github
24 дня назад

go-git: Malicious reference names may modify files outside the reference storage

EPSS

Процентиль: 34%
0.00413
Низкий

6.3 Medium

CVSS3