CVE-2025-48385

EUVD-2025-20678
Git is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-level operations and full access to internals. When cloning a repository Git knows to optionally fetch a bundle advertised by the remote server, which allows the server-side to offload parts of the clone to a CDN. The Git client does not perform sufficient validation of the advertised bundles, which allows the remote side to perform protocol injection. This protocol injection can cause the client to write the fetched bundle to a location controlled by the adversary. The fetched content is fully controlled by the server, which can in the worst case lead to arbitrary code execution. The use of bundle URIs is not enabled by default and can be controlled by the bundle.heuristic config option. Some cases of the vulnerability require that the adversary is in control of where a repository will be cloned to. This either requires social engineering or a recursive clone with submodules. These cases can thus be avoided by disabling recursive clones. This vulnerability is fixed in v2.43.7, v2.44.4, v2.45.4, v2.46.4, v2.47.3, v2.48.2, v2.49.1, and v2.50.1.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
GitHub_MCNA
8.6 HIGH
NETWORK
LOW
NONE
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 40%
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
gitgit
𝑥
< 2.43.7
CNA
Debian logo
Debian Releases
Debian Product
Codename
git
bookworm
1:2.39.5-0+deb12u3
fixed
bookworm (security)
vulnerable
bullseye
1:2.30.2-1+deb11u2
fixed
bullseye (security)
1:2.30.2-1+deb11u5
fixed
forky
1:2.53.0-1
fixed
sid
1:2.53.0-1
fixed
trixie
1:2.47.3-0+deb13u1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
git
bionic
not-affected
focal
not-affected
jammy
not-affected
noble
Fixed 1:2.43.0-1ubuntu7.3
released
oracular
Fixed 1:2.45.2-1ubuntu1.2
released
plucky
Fixed 1:2.48.1-0ubuntu1.1
released
xenial
not-affected
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
git
suse enterprise desktop 15 SP6
2.51.0-150600.3.12.1
fixed
suse enterprise desktop 15 SP7
2.51.0-150600.3.12.1
fixed
suse enterprise sap 15 SP3
2.43.7-150300.10.51.1
fixed
suse enterprise sap 15 SP4
2.43.7-150300.10.51.1
fixed
suse enterprise sap 15 SP5
2.43.7-150300.10.51.1
fixed
suse enterprise sap 15 SP6
2.51.0-150600.3.12.1
fixed
suse enterprise sap 15 SP7
2.51.0-150600.3.12.1
fixed
suse enterprise server 15 SP3
2.43.7-150300.10.51.1
fixed
suse enterprise server 15 SP4
2.43.7-150300.10.51.1
fixed
suse enterprise server 15 SP5
2.43.7-150300.10.51.1
fixed
suse enterprise server 15 SP6
2.51.0-150600.3.12.1
fixed
suse enterprise server 15 SP7
2.51.0-150600.3.12.1
fixed
git-arch
suse enterprise desktop 15 SP6
2.51.0-150600.3.12.1
fixed
suse enterprise desktop 15 SP7
2.51.0-150600.3.12.1
fixed
suse enterprise sap 15 SP3
2.43.7-150300.10.51.1
fixed
suse enterprise sap 15 SP4
2.43.7-150300.10.51.1
fixed
suse enterprise sap 15 SP5
2.43.7-150300.10.51.1
fixed
suse enterprise sap 15 SP6
2.51.0-150600.3.12.1
fixed
suse enterprise sap 15 SP7
2.51.0-150600.3.12.1
fixed
suse enterprise server 15 SP3
2.43.7-150300.10.51.1
fixed
suse enterprise server 15 SP4
2.43.7-150300.10.51.1
fixed
suse enterprise server 15 SP5
2.43.7-150300.10.51.1
fixed
suse enterprise server 15 SP6
2.51.0-150600.3.12.1
fixed
suse enterprise server 15 SP7
2.51.0-150600.3.12.1
fixed
git-core
suse enterprise sap 15 SP3
2.43.7-150300.10.51.1
fixed
suse enterprise sap 15 SP4
2.43.7-150300.10.51.1
fixed
suse enterprise sap 15 SP5
2.43.7-150300.10.51.1
fixed
suse enterprise server 15 SP3
2.43.7-150300.10.51.1
fixed
suse enterprise server 15 SP4
2.43.7-150300.10.51.1
fixed
suse enterprise server 15 SP5
2.43.7-150300.10.51.1
fixed
git-cvs
suse enterprise desktop 15 SP6
2.51.0-150600.3.12.1
fixed
suse enterprise desktop 15 SP7
2.51.0-150600.3.12.1
fixed
suse enterprise sap 15 SP3
2.43.7-150300.10.51.1
fixed
suse enterprise sap 15 SP4
2.43.7-150300.10.51.1
fixed
suse enterprise sap 15 SP5
2.43.7-150300.10.51.1
fixed
suse enterprise sap 15 SP6
2.51.0-150600.3.12.1
fixed
suse enterprise sap 15 SP7
2.51.0-150600.3.12.1
fixed
suse enterprise server 15 SP3
2.43.7-150300.10.51.1
fixed
suse enterprise server 15 SP4
2.43.7-150300.10.51.1
fixed
suse enterprise server 15 SP5
2.43.7-150300.10.51.1
fixed
suse enterprise server 15 SP6
2.51.0-150600.3.12.1
fixed
suse enterprise server 15 SP7
2.51.0-150600.3.12.1
fixed
git-daemon
suse enterprise desktop 15 SP6
2.51.0-150600.3.12.1
fixed
suse enterprise desktop 15 SP7
2.51.0-150600.3.12.1
fixed
suse enterprise sap 15 SP3
2.43.7-150300.10.51.1
fixed
suse enterprise sap 15 SP4
2.43.7-150300.10.51.1
fixed
suse enterprise sap 15 SP5
2.43.7-150300.10.51.1
fixed
suse enterprise sap 15 SP6
2.51.0-150600.3.12.1
fixed
suse enterprise sap 15 SP7
2.51.0-150600.3.12.1
fixed
suse enterprise server 15 SP3
2.43.7-150300.10.51.1
fixed
suse enterprise server 15 SP4
2.43.7-150300.10.51.1
fixed
suse enterprise server 15 SP5
2.43.7-150300.10.51.1
fixed
suse enterprise server 15 SP6
2.51.0-150600.3.12.1
fixed
suse enterprise server 15 SP7
2.51.0-150600.3.12.1
fixed
git-doc
suse enterprise desktop 15 SP6
2.51.0-150600.3.12.1
fixed
suse enterprise desktop 15 SP7
2.51.0-150600.3.12.1
fixed
suse enterprise sap 15 SP3
2.43.7-150300.10.51.1
fixed
suse enterprise sap 15 SP4
2.43.7-150300.10.51.1
fixed
suse enterprise sap 15 SP5
2.43.7-150300.10.51.1
fixed
suse enterprise sap 15 SP6
2.51.0-150600.3.12.1
fixed
suse enterprise sap 15 SP7
2.51.0-150600.3.12.1
fixed
suse enterprise server 15 SP3
2.43.7-150300.10.51.1
fixed
suse enterprise server 15 SP4
2.43.7-150300.10.51.1
fixed
suse enterprise server 15 SP5
2.43.7-150300.10.51.1
fixed
suse enterprise server 15 SP6
2.51.0-150600.3.12.1
fixed
suse enterprise server 15 SP7
2.51.0-150600.3.12.1
fixed
git-email
suse enterprise desktop 15 SP6
2.51.0-150600.3.12.1
fixed
suse enterprise desktop 15 SP7
2.51.0-150600.3.12.1
fixed
suse enterprise sap 15 SP3
2.43.7-150300.10.51.1
fixed
suse enterprise sap 15 SP4
2.43.7-150300.10.51.1
fixed
suse enterprise sap 15 SP5
2.43.7-150300.10.51.1
fixed
suse enterprise sap 15 SP6
2.51.0-150600.3.12.1
fixed
suse enterprise sap 15 SP7
2.51.0-150600.3.12.1
fixed
suse enterprise server 15 SP3
2.43.7-150300.10.51.1
fixed
suse enterprise server 15 SP4
2.43.7-150300.10.51.1
fixed
suse enterprise server 15 SP5
2.43.7-150300.10.51.1
fixed
suse enterprise server 15 SP6
2.51.0-150600.3.12.1
fixed
suse enterprise server 15 SP7
2.51.0-150600.3.12.1
fixed
git-gui
suse enterprise desktop 15 SP6
2.51.0-150600.3.12.1
fixed
suse enterprise desktop 15 SP7
2.51.0-150600.3.12.1
fixed
suse enterprise sap 15 SP3
2.43.7-150300.10.51.1
fixed
suse enterprise sap 15 SP4
2.43.7-150300.10.51.1
fixed
suse enterprise sap 15 SP5
2.43.7-150300.10.51.1
fixed
suse enterprise sap 15 SP6
2.51.0-150600.3.12.1
fixed
suse enterprise sap 15 SP7
2.51.0-150600.3.12.1
fixed
suse enterprise server 15 SP3
2.43.7-150300.10.51.1
fixed
suse enterprise server 15 SP4
2.43.7-150300.10.51.1
fixed
suse enterprise server 15 SP5
2.43.7-150300.10.51.1
fixed
suse enterprise server 15 SP6
2.51.0-150600.3.12.1
fixed
suse enterprise server 15 SP7
2.51.0-150600.3.12.1
fixed
git-lfs
suse enterprise desktop 15 SP6
3.7.0-150600.13.3.1
fixed
suse enterprise desktop 15 SP7
3.7.0-150600.13.3.1
fixed
suse enterprise sap 15 SP6
3.7.0-150600.13.3.1
fixed
suse enterprise sap 15 SP7
3.7.0-150600.13.3.1
fixed
suse enterprise server 15 SP6
3.7.0-150600.13.3.1
fixed
suse enterprise server 15 SP7
3.7.0-150600.13.3.1
fixed
git-svn
suse enterprise desktop 15 SP6
2.51.0-150600.3.12.1
fixed
suse enterprise desktop 15 SP7
2.51.0-150600.3.12.1
fixed
suse enterprise sap 15 SP3
2.43.7-150300.10.51.1
fixed
suse enterprise sap 15 SP4
2.43.7-150300.10.51.1
fixed
suse enterprise sap 15 SP5
2.43.7-150300.10.51.1
fixed
suse enterprise sap 15 SP6
2.51.0-150600.3.12.1
fixed
suse enterprise sap 15 SP7
2.51.0-150600.3.12.1
fixed
suse enterprise server 15 SP3
2.43.7-150300.10.51.1
fixed
suse enterprise server 15 SP4
2.43.7-150300.10.51.1
fixed
suse enterprise server 15 SP5
2.43.7-150300.10.51.1
fixed
suse enterprise server 15 SP6
2.51.0-150600.3.12.1
fixed
suse enterprise server 15 SP7
2.51.0-150600.3.12.1
fixed
git-web
suse enterprise desktop 15 SP6
2.51.0-150600.3.12.1
fixed
suse enterprise desktop 15 SP7
2.51.0-150600.3.12.1
fixed
suse enterprise sap 15 SP3
2.43.7-150300.10.51.1
fixed
suse enterprise sap 15 SP4
2.43.7-150300.10.51.1
fixed
suse enterprise sap 15 SP5
2.43.7-150300.10.51.1
fixed
suse enterprise sap 15 SP6
2.51.0-150600.3.12.1
fixed
suse enterprise sap 15 SP7
2.51.0-150600.3.12.1
fixed
suse enterprise server 15 SP3
2.43.7-150300.10.51.1
fixed
suse enterprise server 15 SP4
2.43.7-150300.10.51.1
fixed
suse enterprise server 15 SP5
2.43.7-150300.10.51.1
fixed
suse enterprise server 15 SP6
2.51.0-150600.3.12.1
fixed
suse enterprise server 15 SP7
2.51.0-150600.3.12.1
fixed
gitk
suse enterprise desktop 15 SP6
2.51.0-150600.3.12.1
fixed
suse enterprise desktop 15 SP7
2.51.0-150600.3.12.1
fixed
suse enterprise sap 15 SP3
2.43.7-150300.10.51.1
fixed
suse enterprise sap 15 SP4
2.43.7-150300.10.51.1
fixed
suse enterprise sap 15 SP5
2.43.7-150300.10.51.1
fixed
suse enterprise sap 15 SP6
2.51.0-150600.3.12.1
fixed
suse enterprise sap 15 SP7
2.51.0-150600.3.12.1
fixed
suse enterprise server 15 SP3
2.43.7-150300.10.51.1
fixed
suse enterprise server 15 SP4
2.43.7-150300.10.51.1
fixed
suse enterprise server 15 SP5
2.43.7-150300.10.51.1
fixed
suse enterprise server 15 SP6
2.51.0-150600.3.12.1
fixed
suse enterprise server 15 SP7
2.51.0-150600.3.12.1
fixed
perl-Git
suse enterprise desktop 15 SP6
2.51.0-150600.3.12.1
fixed
suse enterprise desktop 15 SP7
2.51.0-150600.3.12.1
fixed
suse enterprise sap 15 SP3
2.43.7-150300.10.51.1
fixed
suse enterprise sap 15 SP4
2.43.7-150300.10.51.1
fixed
suse enterprise sap 15 SP5
2.43.7-150300.10.51.1
fixed
suse enterprise sap 15 SP6
2.51.0-150600.3.12.1
fixed
suse enterprise sap 15 SP7
2.51.0-150600.3.12.1
fixed
suse enterprise server 15 SP3
2.43.7-150300.10.51.1
fixed
suse enterprise server 15 SP4
2.43.7-150300.10.51.1
fixed
suse enterprise server 15 SP5
2.43.7-150300.10.51.1
fixed
suse enterprise server 15 SP6
2.51.0-150600.3.12.1
fixed
suse enterprise server 15 SP7
2.51.0-150600.3.12.1
fixed
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
git
RHEL 8
0:2.43.7-1.el8_10
fixed
RHEL 8.8 E4S
0:2.39.5-1.el8_8.2
fixed
RHEL 8.8 TUS
0:2.39.5-1.el8_8.2
fixed
RHEL 9
0:2.47.3-1.el9_6
fixed
git-all
RHEL 8
0:2.43.7-1.el8_10
fixed
RHEL 8.8 E4S
0:2.39.5-1.el8_8.2
fixed
RHEL 8.8 TUS
0:2.39.5-1.el8_8.2
fixed
RHEL 9
0:2.47.3-1.el9_6
fixed
git-core
RHEL 8
0:2.43.7-1.el8_10
fixed
RHEL 8.8 E4S
0:2.39.5-1.el8_8.2
fixed
RHEL 8.8 TUS
0:2.39.5-1.el8_8.2
fixed
RHEL 9
0:2.47.3-1.el9_6
fixed
git-core-doc
RHEL 8
0:2.43.7-1.el8_10
fixed
RHEL 8.8 E4S
0:2.39.5-1.el8_8.2
fixed
RHEL 8.8 TUS
0:2.39.5-1.el8_8.2
fixed
RHEL 9
0:2.47.3-1.el9_6
fixed
git-credential-libsecret
RHEL 8
0:2.43.7-1.el8_10
fixed
RHEL 8.8 E4S
0:2.39.5-1.el8_8.2
fixed
RHEL 8.8 TUS
0:2.39.5-1.el8_8.2
fixed
RHEL 9
0:2.47.3-1.el9_6
fixed
git-daemon
RHEL 8
0:2.43.7-1.el8_10
fixed
RHEL 8.8 E4S
0:2.39.5-1.el8_8.2
fixed
RHEL 8.8 TUS
0:2.39.5-1.el8_8.2
fixed
RHEL 9
0:2.47.3-1.el9_6
fixed
git-email
RHEL 8
0:2.43.7-1.el8_10
fixed
RHEL 8.8 E4S
0:2.39.5-1.el8_8.2
fixed
RHEL 8.8 TUS
0:2.39.5-1.el8_8.2
fixed
RHEL 9
0:2.47.3-1.el9_6
fixed
git-gui
RHEL 8
0:2.43.7-1.el8_10
fixed
RHEL 8.8 E4S
0:2.39.5-1.el8_8.2
fixed
RHEL 8.8 TUS
0:2.39.5-1.el8_8.2
fixed
RHEL 9
0:2.47.3-1.el9_6
fixed
git-instaweb
RHEL 8
0:2.43.7-1.el8_10
fixed
RHEL 8.8 E4S
0:2.39.5-1.el8_8.2
fixed
RHEL 8.8 TUS
0:2.39.5-1.el8_8.2
fixed
RHEL 9
0:2.47.3-1.el9_6
fixed
git-subtree
RHEL 8
0:2.43.7-1.el8_10
fixed
RHEL 8.8 E4S
0:2.39.5-1.el8_8.2
fixed
RHEL 8.8 TUS
0:2.39.5-1.el8_8.2
fixed
RHEL 9
0:2.47.3-1.el9_6
fixed
git-svn
RHEL 8
0:2.43.7-1.el8_10
fixed
RHEL 8.8 E4S
0:2.39.5-1.el8_8.2
fixed
RHEL 8.8 TUS
0:2.39.5-1.el8_8.2
fixed
RHEL 9
0:2.47.3-1.el9_6
fixed
gitk
RHEL 8
0:2.43.7-1.el8_10
fixed
RHEL 8.8 E4S
0:2.39.5-1.el8_8.2
fixed
RHEL 8.8 TUS
0:2.39.5-1.el8_8.2
fixed
RHEL 9
0:2.47.3-1.el9_6
fixed
gitweb
RHEL 8
0:2.43.7-1.el8_10
fixed
RHEL 8.8 E4S
0:2.39.5-1.el8_8.2
fixed
RHEL 8.8 TUS
0:2.39.5-1.el8_8.2
fixed
RHEL 9
0:2.47.3-1.el9_6
fixed
perl-Git
RHEL 8
0:2.43.7-1.el8_10
fixed
RHEL 8.8 E4S
0:2.39.5-1.el8_8.2
fixed
RHEL 8.8 TUS
0:2.39.5-1.el8_8.2
fixed
RHEL 9
0:2.47.3-1.el9_6
fixed
perl-Git-SVN
RHEL 8
0:2.43.7-1.el8_10
fixed
RHEL 8.8 E4S
0:2.39.5-1.el8_8.2
fixed
RHEL 8.8 TUS
0:2.39.5-1.el8_8.2
fixed
RHEL 9
0:2.47.3-1.el9_6
fixed