CVE-2026-41506

EUVD-2026-28596
go-git is an extensible git implementation library written in pure Go. Prior to versions 5.18.0 and 6.0.0-alpha.2, go-git may leak HTTP authentication credentials when following redirects during smart-HTTP clone and fetch operations. This issue has been patched in versions 5.18.0 and 6.0.0-alpha.2.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4.7 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 16%
Affected Products (NVD)
VendorProductVersion
go-git_projectgo-git
𝑥
< 5.18.0
go-git_projectgo-git
6.0.0:alpha1
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
golang-github-go-git-go-git
bookworm
vulnerable
forky
5.19.1-1
fixed
sid
5.19.1-1
fixed
trixie
vulnerable
golang-github-go-git-go-git-v6
forky
vulnerable
sid
6.0.0~alpha.4-1
fixed
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
amazon-ssm-agent
suse enterprise sap 15 SP4
3.3.4624.0-150000.5.37.1
fixed
suse enterprise sap 15 SP5
3.3.4624.0-150000.5.37.1
fixed
suse enterprise sap 15 SP7
3.3.4624.0-150000.5.37.1
fixed
suse enterprise server 15 SP4
3.3.4624.0-150000.5.37.1
fixed
suse enterprise server 15 SP5
3.3.4624.0-150000.5.37.1
fixed
suse enterprise server 15 SP7
3.3.4624.0-150000.5.37.1
fixed
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
amazon-ssm-agent
Amazon Linux 2
0:3.3.4624.0-1.amzn2
fixed
Amazon Linux 2023
0:3.3.4624.0-1.amzn2023
fixed