Количество 16
Количество 16
GHSA-37cx-329c-33x3
go-git improperly verifies data integrity values for .idx and .pack files
CVE-2026-25934
go-git is a highly extensible git implementation library written in pure Go. Prior to 5.16.5, a vulnerability was discovered in go-git whereby data integrity values for .pack and .idx files were not properly verified. This resulted in go-git potentially consuming corrupted files, which would likely result in unexpected errors such as object not found. For context, clients fetch packfiles from upstream Git servers. Those files contain a checksum of their contents, so that clients can perform integrity checks before consuming it. The pack indexes (.idx) are generated locally by go-git, or the git cli, when new .pack files are received and processed. The integrity checks for both files were not being verified correctly. This vulnerability is fixed in 5.16.5.
CVE-2026-25934
go-git is a highly extensible git implementation library written in pure Go. Prior to 5.16.5, a vulnerability was discovered in go-git whereby data integrity values for .pack and .idx files were not properly verified. This resulted in go-git potentially consuming corrupted files, which would likely result in unexpected errors such as object not found. For context, clients fetch packfiles from upstream Git servers. Those files contain a checksum of their contents, so that clients can perform integrity checks before consuming it. The pack indexes (.idx) are generated locally by go-git, or the git cli, when new .pack files are received and processed. The integrity checks for both files were not being verified correctly. This vulnerability is fixed in 5.16.5.
CVE-2026-25934
go-git is a highly extensible git implementation library written in pure Go. Prior to 5.16.5, a vulnerability was discovered in go-git whereby data integrity values for .pack and .idx files were not properly verified. This resulted in go-git potentially consuming corrupted files, which would likely result in unexpected errors such as object not found. For context, clients fetch packfiles from upstream Git servers. Those files contain a checksum of their contents, so that clients can perform integrity checks before consuming it. The pack indexes (.idx) are generated locally by go-git, or the git cli, when new .pack files are received and processed. The integrity checks for both files were not being verified correctly. This vulnerability is fixed in 5.16.5.
CVE-2026-25934
go-git is a highly extensible git implementation library written in pu ...
BDU:2026-05592
Уязвимость библиотеки go-git связана с отсутствием проверки целостности, позволяющая нарушителю вызвать отказ в обслуживании
SUSE-SU-2026:1411-1
Security update for terraform-provider-local, terraform-provider-random, terraform-provider-tls
ROS-20260327-73-0012
Уязвимость go-git
openSUSE-SU-2026:20752-1
Security update for alloy
SUSE-SU-2026:2438-1
Security update for alloy
openSUSE-SU-2026:20702-1
Security update for trivy
openSUSE-SU-2026:20809-1
Security update for trivy
openSUSE-SU-2026:21079-1
Security update for amazon-ssm-agent
SUSE-SU-2026:2468-1
Security update for amazon-ssm-agent
SUSE-SU-2026:2467-1
Security update for amazon-ssm-agent
SUSE-SU-2026:3056-1
Security update for terraform-provider-aws, terraform-provider-azurerm, terraform-provider-external, terraform-provider-google, terraform-provider-helm, terraform-provider-kubernetes, terraform-provider-local, terraform-provider-null, terraform-provider-random, terraform-provider-tls
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-37cx-329c-33x3 go-git improperly verifies data integrity values for .idx and .pack files | CVSS3: 4.3 | 0% Низкий | 6 месяцев назад | |
CVE-2026-25934 go-git is a highly extensible git implementation library written in pure Go. Prior to 5.16.5, a vulnerability was discovered in go-git whereby data integrity values for .pack and .idx files were not properly verified. This resulted in go-git potentially consuming corrupted files, which would likely result in unexpected errors such as object not found. For context, clients fetch packfiles from upstream Git servers. Those files contain a checksum of their contents, so that clients can perform integrity checks before consuming it. The pack indexes (.idx) are generated locally by go-git, or the git cli, when new .pack files are received and processed. The integrity checks for both files were not being verified correctly. This vulnerability is fixed in 5.16.5. | CVSS3: 4.3 | 0% Низкий | 6 месяцев назад | |
CVE-2026-25934 go-git is a highly extensible git implementation library written in pure Go. Prior to 5.16.5, a vulnerability was discovered in go-git whereby data integrity values for .pack and .idx files were not properly verified. This resulted in go-git potentially consuming corrupted files, which would likely result in unexpected errors such as object not found. For context, clients fetch packfiles from upstream Git servers. Those files contain a checksum of their contents, so that clients can perform integrity checks before consuming it. The pack indexes (.idx) are generated locally by go-git, or the git cli, when new .pack files are received and processed. The integrity checks for both files were not being verified correctly. This vulnerability is fixed in 5.16.5. | CVSS3: 4.3 | 0% Низкий | 6 месяцев назад | |
CVE-2026-25934 go-git is a highly extensible git implementation library written in pure Go. Prior to 5.16.5, a vulnerability was discovered in go-git whereby data integrity values for .pack and .idx files were not properly verified. This resulted in go-git potentially consuming corrupted files, which would likely result in unexpected errors such as object not found. For context, clients fetch packfiles from upstream Git servers. Those files contain a checksum of their contents, so that clients can perform integrity checks before consuming it. The pack indexes (.idx) are generated locally by go-git, or the git cli, when new .pack files are received and processed. The integrity checks for both files were not being verified correctly. This vulnerability is fixed in 5.16.5. | CVSS3: 4.3 | 0% Низкий | 6 месяцев назад | |
CVE-2026-25934 go-git is a highly extensible git implementation library written in pu ... | CVSS3: 4.3 | 0% Низкий | 6 месяцев назад | |
BDU:2026-05592 Уязвимость библиотеки go-git связана с отсутствием проверки целостности, позволяющая нарушителю вызвать отказ в обслуживании | CVSS3: 4.3 | 0% Низкий | 6 месяцев назад | |
SUSE-SU-2026:1411-1 Security update for terraform-provider-local, terraform-provider-random, terraform-provider-tls | 4 месяца назад | |||
ROS-20260327-73-0012 Уязвимость go-git | CVSS3: 4.3 | 0% Низкий | 4 месяца назад | |
openSUSE-SU-2026:20752-1 Security update for alloy | 3 месяца назад | |||
SUSE-SU-2026:2438-1 Security update for alloy | около 2 месяцев назад | |||
openSUSE-SU-2026:20702-1 Security update for trivy | 3 месяца назад | |||
openSUSE-SU-2026:20809-1 Security update for trivy | 3 месяца назад | |||
openSUSE-SU-2026:21079-1 Security update for amazon-ssm-agent | около 2 месяцев назад | |||
SUSE-SU-2026:2468-1 Security update for amazon-ssm-agent | около 2 месяцев назад | |||
SUSE-SU-2026:2467-1 Security update for amazon-ssm-agent | около 2 месяцев назад | |||
SUSE-SU-2026:3056-1 Security update for terraform-provider-aws, terraform-provider-azurerm, terraform-provider-external, terraform-provider-google, terraform-provider-helm, terraform-provider-kubernetes, terraform-provider-local, terraform-provider-null, terraform-provider-random, terraform-provider-tls | 22 дня назад |
Уязвимостей на страницу