CVE-2026-32631Patch

LOWCVSS 7.4 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Git for Windows is the Windows port of Git. Versions prior to 2.53.0.windows.3 do not have protections that prevent attackers from obtaining a user's NTLM hash. The NTLM hash can be obtained by tricking users into cloning a malicious repository, or checking out a malicious branch, that accesses an attacker-controlled server. By default, NTLM authentication does not need any user interaction. By brute-forcing the NTLMv2 hash (which is expensive, but possible), credentials can be extracted. This issue has been fixed in version 2.53.0.windows.3.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-200

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-04-15); latest day: 1
  • 3 total mentions across 3 days

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-04-15: 1Mentions · 2026-04-16: 1Mentions · 2026-04-20: 1Patch / Workaround · 2026-04-15: 1Technical Details · 2026-04-15: 1Technical Details · 2026-04-16: 104-1504-1604-20
Signal classification3 categories
Patch
133.3%
Disclosure
133.3%
General
133.3%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-04-151
Patch1
2026-04-161
Disclosure1
2026-04-201
General1
Full discourse3 posts
  • VulnTracker@vuln_tracker
    General

    @0x534c Your devs clone repos all day. CVE-2026-32631 turns that into credential theft. We catch it. Does your stack. http://Vulntracker.io

    Post summary

    The tweet references CVE‑2026‑32631 as a credential theft vector but provides no PoC, exploit code, technical details, or patch information.

    0000058
    571 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-32631 Git for Windows is the Windows port of Git. Versions prior to http://2.53.0.windows.3 do not have protections that prevent attackers from obtaining a user's NTLM hash. The N… https://www.cve.org/CVERecord?id=CVE-2026-32631

    Post summary

    Git for Windows versions before 2.53.0.windows.3 lack protection against NTLM hash extraction, exposing users to credential theft.

    0000085
    57.2K followersView on X
  • Red Hornet Intel@RedHornet_Intel
    Patch

    CVE-2026-32631 | git-for-windows git | Vulnerability Description Git for Windows prior to http://2.53.0.windows.3 lacks protections against NTLM hash leakage. Attackers trick users into cloning a malicious repository or checking out a malicious branch, causing Git to access an attacker-controlled server and leak the user's NTLMv2 hash via unauth NTLM auth. Brute-forcing the hash enables credential extraction. Severity: High Exploitation: Unknown Public PoC: Unknown Patch Available: Yes Affected Product: git-for-windows git Affected Version: < http://2.53.0.windows.3 Sources Research: https://github.com/git-for-windows/git/security/advisories/GHSA-9j5h-h4m7-85hx Research: https://github.com/git-for-windows/git/releases/tag/v2.53.0.windows.3

    Post summary

    Git for Windows versions prior to 2.53.0.windows.3 are susceptible to NTLM hash leakage when accessing malicious repos, but a patch is available in the 2.53.0.windows.3 release.

    0000099
    8 followersView on X

Explore more