Data Integrity Vulnerability in Go-Git Library by The Go Project
CVE-2026-25934
What is CVE-2026-25934?
The go-git library, an extensible implementation of Git written in Go, has a vulnerability where it fails to properly verify data integrity for .pack and .idx files prior to version 5.16.5. This oversight allows the library to potentially process corrupted files, which may lead to errors such as 'object not found'. When clients fetch packfiles from upstream Git servers, they are expected to perform integrity checks using checksums. However, go-git was not reliably conducting these checks, increasing the risk of data corruption. This issue has been addressed in version 5.16.5.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
go-git < 5.16.5
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
