CVE-2026-25934Disclosure(go-git_project / go-git)

LOWCVSS 4.3 · MEDIUM

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch go-git_project go-git systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

go-git is a highly extensible git implementation library written in pure Go. Prior to 5.16.5, a vulnerability was discovered in go-git whereby data integrity values for .pack and .idx files were not properly verified. This resulted in go-git potentially consuming corrupted files, which would likely result in unexpected errors such as object not found. For context, clients fetch packfiles from upstream Git servers. Those files contain a checksum of their contents, so that clients can perform integrity checks before consuming it. The pack indexes (.idx) are generated locally by go-git, or the git cli, when new .pack files are received and processed. The integrity checks for both files were not being verified correctly. This vulnerability is fixed in 5.16.5.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-354

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • go-git

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 2 mentions (2026-02-10); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Products
go-git

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-02-09: 1Mentions · 2026-02-10: 2Mentions · 2026-04-17: 1PoC Mentioned / Linked · 2026-04-17: 1Patch / Workaround · 2026-04-17: 1Technical Details · 2026-02-09: 1Technical Details · 2026-02-10: 2Technical Details · 2026-04-17: 102-0902-1004-17
Signal classification2 categories
Disclosure
375.0%
Patch
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-02-091
Disclosure1
2026-02-102
Disclosure2
2026-04-171
Patch1
Full discourse4 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-25934 Go-Git Packfile and Index File Integrity Verification Vulnerability Before 5.16.5 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-25934

    Post summary

    A new Go‑Git vulnerability (CVE‑2026‑25934) affecting versions before 5.16.5 was identified, but no PoC, exploit, or patch information is provided.

    0001090
    4.0K followersView on X
  • ThreatCluster@threatcluster
    Patch

    BREAKING: openSUSE Leap 15.6 and Ubuntu Server 22.04 patch critical Terraform provider flaws CVE-2026-25934 and CVE-2026-33186, with HTTP/2 :path bug rated CVSS 9.1 and PoC released 2026-04-07. https://threatcluster.io/cluster/critical-vulnerabilities-in-terraform-providers-affecting-op-588dd59e

    Post summary

    OpenSUSE Leap 15.6 and Ubuntu Server 22.04 have released critical patches for Terraform provider CVEs 2026-25934 and 2026-33186, with a public PoC and a CVSS 9.1 rating for an HTTP/2 :path flaw.

    00000149
    155 followersView on X
  • cvereports@_cvereports
    Disclosure

    CVE-2026-25934: Broken Seals: How go-git Forgot to Check the Receipt (CVE-2026-25934) A fundamental data integrity flaw in the popular `go-git` library allowed for the consumption of corrupted or malicious Git packfiles without detection. By failing t... https://cvereports.com/reports/CVE-2026-25934

    Post summary

    The report exposes a data integrity issue in the go‑git library enabling processing of malicious packfiles, without providing PoC, exploit code, or mitigation information.

    0000051
    27 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-25934 go-git is a highly extensible git implementation library written in pure Go. Prior to 5.16.5, a vulnerability was discovered in go-git whereby data integrity values f… https://www.cve.org/CVERecord?id=CVE-2026-25934

    Post summary

    CVE‑2026‑25934 is a data‑integrity issue in go‑git before version 5.16.5, but no PoC, exploit, patch, or active exploitation details are provided.

    00000262
    56.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appgo-git_projectgo-git-go-

Explore more