PT-2026-33110 · Unknown · Git For Windows

Published

2026-04-15

·

Updated

2026-04-20

·

CVE-2026-32631

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Git for Windows versions prior to 2.53.0.windows.3
Description Git for Windows lacks protections that prevent attackers from obtaining a user's NTLM hash. An attacker can obtain the NTLMv2 hash by tricking users into cloning a malicious repository or checking out a malicious branch that accesses a server controlled by the attacker. Because NTLM authentication does not require user interaction by default, the hash can be leaked automatically. Credentials can then be extracted by brute-forcing the NTLMv2 hash.
Recommendations Update to version 2.53.0.windows.3.

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

BDU:2026-05824
CVE-2026-32631

Affected Products

Git For Windows