Git Scm maintains a narrowly focused product line—the Git distributed version control system—that despite limited portfolio breadth occupies an exceptionally prominent position in the software development and supply chain landscape due to its nearly universal adoption across both open-source and enterprise environments. The vendor's vulnerability disclosures reflect the complexity of parsing untrusted repository data and managing cryptographic operations in a tool that processes content from diverse sources. Defenders should treat Git updates as broadly applicable to development infrastructure and build pipelines, since exposure typically extends across every developer workstation and CI/CD system that pulls from potentially compromised repositories. Live exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Git Scm over time
Signals from CVEs in this vendor scope (41 CVEs).
41 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-17456CRITICAL Git before 2.14.5, 2.15.x before 2.15.3, 2.16.x before 2.16.5, 2.17.x before 2.17.2, 2.18.x before 2.18.1, and 2.19.x before 2.19.1 allows remote code execution during processing o | Oct 6, 2018 | 9.8 | 91 | NO | YES |
CVE-2017-1000117HIGH A malicious third-party can give a crafted "ssh://..." URL to an unsuspecting victim, and an attempt to visit the URL can result in any program that exists on the victim's machine | Oct 5, 2017 | 8.8 | 85 | NO | YES |
CVE-2021-21300HIGH Git is an open-source distributed revision control system. In affected versions of Git a specially crafted repository that contains symbolic links as well as files using a clean/sm | Mar 9, 2021 | 7.5 | 82 | NO | YES |
CVE-2014-9390CRITICAL Git before 1.8.5.6, 1.9.x before 1.9.5, 2.0.x before 2.0.5, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 on Windows and OS X; Mercurial before 3.2.3 on Windows and OS X; Apple Xcode | Feb 12, 2020 | 9.8 | 76 | NO | YES |
CVE-2025-48384HIGH Git is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-level operations and full access to internals. When reading | Jul 8, 2025 | 8.0 | 66 | YES | NO |
CVE-2022-23521CRITICAL Git is distributed revision control system. gitattributes are a mechanism to allow defining attributes for paths. These attributes can be defined by adding a `.gitattributes` file | Jan 17, 2023 | 9.8 | 64 | NO | NO |
CVE-2022-41903CRITICAL Git is distributed revision control system. `git log` can display commits in an arbitrary format using its `--format` specifiers. This functionality is also exposed to `git archive | Jan 17, 2023 | 9.8 | 57 | NO | NO |
CVE-2018-11235HIGH In Git before 2.13.7, 2.14.x before 2.14.4, 2.15.x before 2.15.2, 2.16.x before 2.16.4, and 2.17.x before 2.17.1, remote code execution can occur. With a crafted .gitmodules file, | May 30, 2018 | 7.8 | 53 | NO | NO |
CVE-2023-25652HIGH Git is a revision control system. Prior to versions 2.30.9, 2.31.8, 2.32.7, 2.33.8, 2.34.8, 2.35.8, 2.36.6, 2.37.7, 2.38.5, 2.39.3, and 2.40.1, by feeding specially crafted input t | Apr 25, 2023 | 7.5 | 52 | NO | NO |
CVE-2017-14867HIGH Git before 2.10.5, 2.11.x before 2.11.4, 2.12.x before 2.12.5, 2.13.x before 2.13.6, and 2.14.x before 2.14.2 uses unsafe Perl scripts to support subcommands such as cvsserver, whi | Sep 29, 2017 | 8.8 | 46 | NO | NO |
Signals from CVEs in this vendor scope (41 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Git Scm.
Media articles that mention a CVE ID that affects a product developed by Git Scm — matched by CVE ID, not by vendor name.