PT-2026-39697 · Go-Git · Go-Git

·

CVE-2026-45022

·

Published

2026-05-11

·

Updated

2026-07-24

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions go-git versions prior to v5
Description go-git may parse malformed Git objects differently than upstream Git. When commit or tag objects contain ambiguous or malformed headers, the decoded representation in go-git may expose values that differ from how Git interprets or rejects the same object. Furthermore, commit signing and verification logic operates on commit data reconstructed from the parsed representation instead of the original raw object bytes. This can lead to go-git signing or verifying a commit payload that is not byte-for-byte equivalent to the object stored in the repository, potentially making a signature appear valid for a commit with metadata that differs from the intended signed object.
Recommendations Upgrade to a supported version of go-git (v5 or later).

Exploit

Fix

Insufficient Verification of Data Authenticity

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CLEANSTART-2026-AQ65185
CLEANSTART-2026-BG69533
CLEANSTART-2026-CP15003
CLEANSTART-2026-DM19620
CLEANSTART-2026-EH36582
CLEANSTART-2026-ES72297
CLEANSTART-2026-HO16255
CLEANSTART-2026-JW97006
CLEANSTART-2026-KL41807
CLEANSTART-2026-KQ90880
CLEANSTART-2026-MY68881
CLEANSTART-2026-OS93204
CLEANSTART-2026-PD78752
CLEANSTART-2026-QP84300
CLEANSTART-2026-QT53274
CLEANSTART-2026-VD47610
CLEANSTART-2026-WF25734
CLEANSTART-2026-WY21381
CVE-2026-45022
GHSA-389R-GV7P-R3RP
GO-2026-5074
OPENSUSE-SU-2026:10769-1

Affected Products

Go-Git