Go Git is a lightweight Git implementation written in Go that is embedded across development tools, container platforms, and infrastructure software despite its narrow product scope. The vendor's vulnerability history centers on the core Git library's handling of repository operations and protocol interactions. Defenders tracking this vendor should prioritize updates given its deep presence in the supply chain; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Go Git Project over time
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-45570CRITICAL go-git is an extensible git implementation library written in pure Go. Prior to 5.19.1 and 6.0.0-alpha.4, go-git's SSH transport constructs the remote exec command by wrapping the | May 27, 2026 | 9.6 | 36 | NO | NO |
CVE-2025-21613CRITICAL go-git is a highly extensible git implementation library written in pure Go. An argument injection vulnerability was discovered in go-git versions prior to v5.13. Successful exploi | Jan 6, 2025 | 9.8 | 30 | NO | NO |
CVE-2023-49569CRITICAL A path traversal vulnerability was discovered in go-git versions prior to v5.11. This vulnerability allows an attacker to create and amend files across the filesystem. In the worse | Jan 12, 2024 | 9.8 | 28 | NO | NO |
CVE-2026-41506HIGH go-git is an extensible git implementation library written in pure Go. Prior to versions 5.18.0 and 6.0.0-alpha.2, go-git may leak HTTP authentication credentials when following re | May 8, 2026 | 7.4 | 27 | NO | NO |
CVE-2026-45022HIGH go-git is an extensible git implementation library written in pure Go. Prior to 5.19.0 and 6.0.0-alpha.3, go-git may parse malformed Git objects in a way that differs from upstream | May 27, 2026 | 7.5 | 26 | NO | NO |
CVE-2026-45571MEDIUM go-git is an extensible git implementation library written in pure Go. Prior to 5.19.1 and 6.0.0-alpha.4, a path validation issue in go-git could allow crafted repository data to a | May 27, 2026 | 5.4 | 25 | NO | NO |
CVE-2025-21614HIGH go-git is a highly extensible git implementation library written in pure Go. A denial of service (DoS) vulnerability was discovered in go-git versions prior to v5.13. This vulnerab | Jan 6, 2025 | 7.5 | 23 | NO | NO |
CVE-2026-34165MEDIUM go-git is an extensible git implementation library written in pure Go. From version 5.0.0 to before version 5.17.1, a vulnerability has been identified in which a maliciously craft | Mar 31, 2026 | 5.0 | 21 | NO | NO |
CVE-2023-49568HIGH A denial of service (DoS) vulnerability was discovered in go-git versions prior to v5.11. This vulnerability allows an attacker to perform denial of service attacks by providing sp | Jan 12, 2024 | 7.5 | 21 | NO | NO |
CVE-2026-25934MEDIUM go-git is a highly extensible git implementation library written in pure Go. Prior to 5.16.5, a vulnerability was discovered in go-git whereby data integrity values for .pack and . | Feb 9, 2026 | 4.3 | 19 | NO | NO |
Signals from CVEs in this vendor scope (11 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Go Git Project.
Media articles that mention a CVE ID that affects a product developed by Go Git Project — matched by CVE ID, not by vendor name.