go-git is an extensible git implementation library written in pure Go. Prior to versions 5.18.0 and 6.0.0-alpha.2, go-git may leak HTTP authentication credentials when following redirects during smart-HTTP clone and fetch operations. This issue has been patched in versions 5.18.0 and 6.0.0-alpha.2.
https://github.com/go-git/go-git/security/advisories/GHSA-3xc5-wrhm-f963
https://github.com/go-git/go-git/releases/tag/v6.0.0-alpha.2
Published: 2026-05-08
Updated: 2026-05-12
Named Vulnerability: GO-2026-5105Named Vulnerability: GHSA-3xc5-wrhm-f963
Base Score: 7.8
Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:N/A:N
Severity: High
Base Score: 7.4
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N
Severity: High
EPSS: 0.00259