CVE-2026-33762

go-git is an extensible git implementation library written in pure Go. Prior to version 5.17.1, go-git’s index decoder for format version 4 fails to validate the path name prefix length before applying it to the previously decoded path name. A maliciously crafted index file can trigger an out-of-bounds slice operation, resulting in a runtime panic during normal index parsing. This issue only affects Git index format version 4. Earlier formats (go-git supports only v2 and v3) are not vulnerable to this issue. This issue has been patched in version 5.17.1.
Configurations

Configuration 1 (hide)

cpe:2.3:a:go-git_project:go-git:*:*:*:*:*:go:*:*

History

24 Jul 2026, 21:10

Type Values Removed Values Added
Summary
  • (es) go-git es una biblioteca de implementación de Git extensible escrita en Go puro. Antes de la versión 5.17.1, el decodificador de índice de go-git para la versión 4 del formato no valida la longitud del prefijo del nombre de ruta antes de aplicarlo al nombre de ruta decodificado previamente. Un archivo de índice creado maliciosamente puede desencadenar una operación de segmento fuera de límites, lo que resulta en un pánico en tiempo de ejecución durante el análisis normal del índice. Este problema solo afecta a la versión 4 del formato de índice de Git. Formatos anteriores (go-git solo soporta v2 y v3) no son vulnerables a este problema. Este problema ha sido parcheado en la versión 5.17.1.

02 Apr 2026, 16:49

Type Values Removed Values Added
CPE cpe:2.3:a:go-git_project:go-git:*:*:*:*:*:go:*:*
First Time Go-git Project
Go-git Project go-git
References () https://github.com/go-git/go-git/releases/tag/v5.17.1 - () https://github.com/go-git/go-git/releases/tag/v5.17.1 - Product, Release Notes
References () https://github.com/go-git/go-git/security/advisories/GHSA-gm2x-2g9h-ccm8 - () https://github.com/go-git/go-git/security/advisories/GHSA-gm2x-2g9h-ccm8 - Vendor Advisory

31 Mar 2026, 15:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-31 15:16

Updated : 2026-07-24 21:10


NVD link : CVE-2026-33762

Mitre link : CVE-2026-33762

CVE.ORG link : CVE-2026-33762


JSON object : View

Products Affected

go-git_project

  • go-git
CWE
CWE-129

Improper Validation of Array Index