Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Git Scm

First CVE: Jan 20, 2009Active for: 18 yearsTotal CVEs: 82

Git Scm maintains a narrowly focused product line—the Git distributed version control system—that despite limited portfolio breadth occupies an exceptionally prominent position in the software development and supply chain landscape due to its nearly universal adoption across both open-source and enterprise environments. The vendor's vulnerability disclosures reflect the complexity of parsing untrusted repository data and managing cryptographic operations in a tool that processes content from diverse sources. Defenders should treat Git updates as broadly applicable to development infrastructure and build pipelines, since exposure typically extends across every developer workstation and CI/CD system that pulls from potentially compromised repositories. Live exploitation activity, severity distribution, and exposure counts are shown alongside this summary.

FAUCET AI Generated
41
Total CVEs
More Total CVEs than 98% of tracked vendors
3.2
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 94% of tracked vendors
7.6
Avg CVSS Score
Higher Avg CVSS Score than 72% of tracked vendors
2.4%
In CISA KEV
Higher KEV Rate than 99% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Git Scm over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 20, 2009
17 years ago
Most Recent CVE
Jul 8, 2025
382 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (41 CVEs).

41 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2018-17456CRITICAL
Git before 2.14.5, 2.15.x before 2.15.3, 2.16.x before 2.16.5, 2.17.x before 2.17.2, 2.18.x before 2.18.1, and 2.19.x before 2.19.1 allows remote code execution during processing o
Oct 6, 20189.891NOYES
CVE-2017-1000117HIGH
A malicious third-party can give a crafted "ssh://..." URL to an unsuspecting victim, and an attempt to visit the URL can result in any program that exists on the victim's machine
Oct 5, 20178.885NOYES
CVE-2021-21300HIGH
Git is an open-source distributed revision control system. In affected versions of Git a specially crafted repository that contains symbolic links as well as files using a clean/sm
Mar 9, 20217.582NOYES
CVE-2014-9390CRITICAL
Git before 1.8.5.6, 1.9.x before 1.9.5, 2.0.x before 2.0.5, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 on Windows and OS X; Mercurial before 3.2.3 on Windows and OS X; Apple Xcode
Feb 12, 20209.876NOYES
CVE-2025-48384HIGH
Git is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-level operations and full access to internals. When reading
Jul 8, 20258.066YESNO
CVE-2022-23521CRITICAL
Git is distributed revision control system. gitattributes are a mechanism to allow defining attributes for paths. These attributes can be defined by adding a `.gitattributes` file
Jan 17, 20239.864NONO
CVE-2022-41903CRITICAL
Git is distributed revision control system. `git log` can display commits in an arbitrary format using its `--format` specifiers. This functionality is also exposed to `git archive
Jan 17, 20239.857NONO
CVE-2018-11235HIGH
In Git before 2.13.7, 2.14.x before 2.14.4, 2.15.x before 2.15.2, 2.16.x before 2.16.4, and 2.17.x before 2.17.1, remote code execution can occur. With a crafted .gitmodules file,
May 30, 20187.853NONO
CVE-2023-25652HIGH
Git is a revision control system. Prior to versions 2.30.9, 2.31.8, 2.32.7, 2.33.8, 2.34.8, 2.35.8, 2.36.6, 2.37.7, 2.38.5, 2.39.3, and 2.40.1, by feeding specially crafted input t
Apr 25, 20237.552NONO
CVE-2017-14867HIGH
Git before 2.10.5, 2.11.x before 2.11.4, 2.12.x before 2.12.5, 2.13.x before 2.13.6, and 2.14.x before 2.14.2 uses unsafe Perl scripts to support subcommands such as cvsserver, whi
Sep 29, 20178.846NONO
View all 41 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products41 CVEs
15%
61%
20%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local14 (34.1%)
Network23 (56.1%)
Unknown4 (9.8%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low34 (82.9%)
High3 (7.3%)
Unknown4 (9.8%)
User Interaction
None19 (46.3%)
Unknown4 (9.8%)
Required18 (43.9%)
Privileges Required
Low5 (12.2%)
High0 (0.0%)
None32 (78.0%)
Unknown4 (9.8%)

Exploit Exposure

Signals from CVEs in this vendor scope (41 CVEs).

CISA KEV
1 CVE
2.4% of CVEs· 99th percentile
Metasploit
4 CVEs
9.8% of CVEs· 98th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
3 CVEs
7.3% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Git Scm.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Git Scm — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Git Scm's Products

View all 5 CNAs →

Top CWEs