{"id":"CVE-2026-25934","title":"go-git/go-git: go-git: Data integrity issue due to improper verification of pack and index files (CVE-2026-25934)","summary":"A flaw was found in go-git, a library for Git implementation in Go. This vulnerability allows a remote attacker to provide specially crafted Git pack or index files that are not properly verified for data integrity. Successful exploitation…","severity":"medium","cvss":4.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N","cvssSource":"vendor","cwe":"CWE-354","vendor":"Red Hat","product":"Red Hat Openshift Data Foundation 4.22","affected":["assisted_installer_for_red_hat_openshift_container_platform 2","builds_for_red_hat_openshift","confidential_compute_attestation","external_secrets_operator_for_red_hat_openshift","kernel_module_management_operator_for_red_hat_openshift","logging_subsystem_for_red_hat_openshift","machine_deletion_remediation_operator","migration_toolkit_for_containers","migration_toolkit_for_virtualization","multicluster_engine_for_kubernetes","network_observability_operator","node_healthcheck_operator","openshift_api_for_data_protection","openshift_developer_tools_and_services","openshift_pipelines","openshift_serverless","openshift_service_mesh 2","openshift_service_mesh 3","pen_drive_powered_by_red_hat_lightspeed","power_monitoring_for_red_hat_openshift","advanced_cluster_management_for_kubernetes 2","advanced_cluster_security 4","ansible_automation_platform 2","build_of_kueue","edge_manager 1","enterprise_linux 8","enterprise_linux 9","openshift_ai_rhoai","openshift_container_platform 4","openshift_dev_workspaces_operator","openshift_for_windows_containers","openshift_gitops","openshift_virtualization 4","openstack_platform 16.2","openstack_platform 17.1","openstack_platform 18.0","trusted_artifact_signer","openshift_data_foundation 4.22"],"patched":["openshift_data_foundation 4.22"],"published":"2026-02-09","updated":"2026-09-21","sourceUpdated":"2026-09-21T17:22:37+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-25934.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-25934.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-25934"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2438332"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-25934"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-25934"},{"url":"https://github.com/go-git/go-git/releases/tag/v5.16.5"},{"url":"https://github.com/go-git/go-git/security/advisories/GHSA-37cx-329c-33x3"},{"url":"https://access.redhat.com/errata/RHSA-2026:37387"},{"url":"https://github.com/go-git/go-git"}],"tags":["csaf","vex","red-hat","osv","go"],"epss":0.00141,"epssPercentile":0.03806,"aliases":["GHSA-37cx-329c-33x3","GO-2026-4473"],"ecosystem":"go","ingestedAt":"2026-09-12T03:13:01.748Z","slug":"CVE-2026-25934","body":"## Overview\n\nA flaw was found in go-git, a library for Git implementation in Go. This vulnerability allows a remote attacker to provide specially crafted Git pack or index files that are not properly verified for data integrity. Successful exploitation could lead to the go-git library processing corrupted data, which may result in unexpected application errors such as 'object not found'.\n\n## Vendor advisories\n\n- **RHSA-2026:37387** · Red Hat · fixed in: Red Hat Openshift Data Foundation 4.22 · released 2026-07-09 · [advisory](https://access.redhat.com/errata/RHSA-2026:37387)\n- **Red Hat VEX** · Moderate · affected: Assisted Installer for Red Hat OpenShift Container Platform 2, Builds for Red Hat OpenShift, Confidential Compute Attestation, External Secrets Operator for Red Hat OpenShift, Kernel Module Management Operator for Red Hat Openshift, Logging Subsystem for Red Hat OpenShift, … · no fix planned: Assisted Installer for Red Hat OpenShift Container Platform 2, Builds for Red Hat OpenShift, Confidential Compute Attestation, External Secrets Operator for Red Hat OpenShift, … · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-25934.json)\n\n**go-git/go-git: go-git: Data integrity issue due to improper verification of pack and index files** — rated Moderate by Red Hat. Released 2026-02-09, updated 2026-09-21.\n\nAffected:\n\n- Assisted Installer for Red Hat OpenShift Container Platform 2\n- Builds for Red Hat OpenShift\n- Confidential Compute Attestation\n- External Secrets Operator for Red Hat OpenShift\n- Kernel Module Management Operator for Red Hat Openshift\n- Logging Subsystem for Red Hat OpenShift\n- Machine Deletion Remediation Operator\n- Migration Toolkit for Containers\n- Migration Toolkit for Virtualization\n- Multicluster Engine for Kubernetes\n- Network Observability Operator\n- Node HealthCheck Operator\n- OpenShift API for Data Protection\n- OpenShift Developer Tools and Services\n- OpenShift Pipelines\n- OpenShift Serverless\n- OpenShift Service Mesh 2\n- OpenShift Service Mesh 3\n- Pen Drive Powered by Red Hat Lightspeed\n- Power monitoring for Red Hat OpenShift\n- Red Hat Advanced Cluster Management for Kubernetes 2\n- Red Hat Advanced Cluster Security 4\n- Red Hat Ansible Automation Platform 2\n- Red Hat Build of Kueue\n- Red Hat Edge Manager 1\n- Red Hat Enterprise Linux 8\n- Red Hat Enterprise Linux 9\n- Red Hat OpenShift AI (RHOAI)\n- Red Hat OpenShift Container Platform 4\n- Red Hat OpenShift Dev Workspaces Operator\n- Red Hat OpenShift for Windows Containers\n- Red Hat OpenShift GitOps\n- Red Hat OpenShift Virtualization 4\n- Red Hat OpenStack Platform 16.2\n- Red Hat OpenStack Platform 17.1\n- Red Hat OpenStack Platform 18.0\n- Red Hat Trusted Artifact Signer\n\nFixed:\n\n- Red Hat Openshift Data Foundation 4.22\n\nNo fix planned:\n\n- Assisted Installer for Red Hat OpenShift Container Platform 2\n- Builds for Red Hat OpenShift\n- Confidential Compute Attestation\n- External Secrets Operator for Red Hat OpenShift\n- Kernel Module Management Operator for Red Hat Openshift\n- Logging Subsystem for Red Hat OpenShift\n- Machine Deletion Remediation Operator\n- Migration Toolkit for Containers\n- Migration Toolkit for Virtualization\n- Multicluster Engine for Kubernetes\n- Network Observability Operator\n- Node HealthCheck Operator\n- OpenShift API for Data Protection\n- OpenShift Developer Tools and Services\n- OpenShift Pipelines\n- OpenShift Serverless\n- OpenShift Service Mesh 2\n- OpenShift Service Mesh 3\n- Pen Drive Powered by Red Hat Lightspeed\n- Power monitoring for Red Hat OpenShift\n- Red Hat Advanced Cluster Management for Kubernetes 2\n- Red Hat Advanced Cluster Security 4\n- Red Hat Ansible Automation Platform 2\n- Red Hat Build of Kueue\n- Red Hat Edge Manager 1\n- Red Hat Enterprise Linux 8\n- Red Hat Enterprise Linux 9\n- Red Hat OpenShift AI (RHOAI)\n- Red Hat OpenShift Container Platform 4\n- Red Hat OpenShift Dev Workspaces Operator\n- Red Hat OpenShift for Windows Containers\n- Red Hat OpenShift GitOps\n- Red Hat OpenShift Virtualization 4\n- Red Hat OpenStack Platform 16.2\n- Red Hat OpenStack Platform 17.1\n- Red Hat OpenStack Platform 18.0\n- Red Hat Trusted Artifact Signer\n\nNot affected:\n\n- Red Hat Openshift Data Foundation 4.22\n\n## Remediation\n\nBefore applying this update, make sure all previously released errata\nrelevant to your system have been applied.\n\nFor details on how to apply this update, refer to:\n\nhttps://docs.redhat.com/en/documentation/red_hat_openshift_data_foundation/4.22/html/updating_openshift_data_foundation/updating-ocs-to-odf_rhodf https://access.redhat.com/errata/RHSA-2026:37387\n\n## Package advisory (CVE-2026-25934)\n\nAffected packages:\n\n- `github.com/go-git/go-git/v5 < 5.16.5`\n\nPatched in:\n\n- `github.com/go-git/go-git/v5 5.16.5`\n\nSource: https://osv.dev/vulnerability/GHSA-37cx-329c-33x3","depth":"sunlit","depthScore":24,"depthScoreParts":{"impact":23.7,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}