{"id":"CVE-2026-33762","aliases":["GHSA-gm2x-2g9h-ccm8","GO-2026-4909"],"url":"https://o3.security/vulnerability/CVE-2026-33762","summary":"go-git: Missing validation decoding Index v4 files leads to panic","details":"### Impact\n\n`go-git`’s index decoder for format version 4 fails to validate the path name prefix length before applying it to the previously decoded path name. A maliciously crafted index file can trigger an out-of-bounds slice operation, resulting in a runtime panic during normal index parsing.\n\nThis issue only affects Git index format version 4. Earlier formats (`go-git` supports only `v2` and `v3`) are not vulnerable to this issue.\n\nAn attacker able to supply a crafted `.git/index` file can cause applications using go-git to panic while reading the index. If the application does not recover from panics, this results in process termination, leading to a denial-of-service (DoS) condition.\n\nExploitation requires the ability to modify or inject a Git index file within the local repository in disk. This typically implies write access to the `.git` directory.\n\n### Patches\n\nUsers should upgrade to `v5.17.1`, or the latest `v6` [pseudo-version](https://go.dev/ref/mod#pseudo-versions), in order to mitigate this vulnerability.\n\n### Credit\n\ngo-git maintainers thank @kq5y for finding and reporting this issue privately to the `go-git` project.","published":"2026-03-31T13:47:42.378Z","modified":"2026-08-12T03:51:13.666485990Z","cvss":{"score":2.8,"severity":"LOW","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L"},"epss":{"score":0.00153,"percentile":0.0467,"asOf":"2026-08-24"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/go-git/go-git/v5","fixedVersion":"5.17.1"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/go-git/go-git/releases/tag/v5.17.1"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/33xxx/CVE-2026-33762.json"},{"type":"ADVISORY","url":"https://github.com/go-git/go-git/security/advisories/GHSA-gm2x-2g9h-ccm8"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-33762"},{"type":"PACKAGE","url":"https://github.com/go-git/go-git"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:13.666485990Z"}}