PT-2026-37125 · Go-Git+1 · Go-Git+1

·

CVE-2026-41506

·

Published

2026-04-17

·

Updated

2026-07-24

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions go-git versions prior to 5.18.0 go-git versions prior to 6.0.0-alpha.2
Description During smart-HTTP clone and fetch operations, the library may leak HTTP authentication credentials when following redirects. If a remote repository responds to the initial '/info/refs' request with a redirect to a different host, the session endpoint is updated to the redirected location and the original authentication, such as Authorization headers, is reused for subsequent requests. This allows an attacker controlling the redirect target to capture credentials and potentially access the victim's repositories or other resources. This issue occurs when interacting with untrusted or misconfigured Git servers or when using unsecured HTTP connections.
Recommendations Update to version 5.18.0. Update to version 6.0.0-alpha.2.

Exploit

Fix

Insufficiently Protected Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-10777
CLEANSTART-2026-EH36582
CLEANSTART-2026-GN78570
CLEANSTART-2026-HO16255
CLEANSTART-2026-KL41807
CLEANSTART-2026-NT80635
CLEANSTART-2026-PD78752
CLEANSTART-2026-QT53274
CLEANSTART-2026-VT65447
CLEANSTART-2026-WF25734
CVE-2026-41506
GHSA-3XC5-WRHM-F963
GO-2026-5105
OPENSUSE-SU-2026:10765-1
OPENSUSE-SU-2026:10771-1
OPENSUSE-SU-2026:10803-1
OPENSUSE-SU-2026:10830-1
OPENSUSE-SU-2026:10967-1
OPENSUSE-SU-2026:20770-1
OPENSUSE-SU-2026:20809-1
OPENSUSE-SU-2026:21079-1
OPENSUSE-SU-2026:21210-1
RHSA-2026:17669
SUSE-SU-2026:22157-1
SUSE-SU-2026:22242-1
SUSE-SU-2026:22249-1
SUSE-SU-2026:22558-1
SUSE-SU-2026:2467-1
SUSE-SU-2026:2468-1
SUSE-SU-2026:2665-1
SUSE-SU-2026:3056-1

Affected Products

Red Os
Go-Git