{"id":"CVE-2026-71556","title":"go-git is an extensible git implementation library written in pure Go","summary":"go-git is an extensible git implementation library written in pure Go. Prior to 5.19.2 and 6.0.0-alpha.5, worktree operations (including checkout, status, and add) resolve symbolic links inside the working tree without confining resoluti…","severity":"high","cvss":7.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L","cwe":["CWE-59"],"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4","affected":["assisted_installer_for_red_hat_openshift_container_platform 2","builds_for_red_hat_openshift","compliance_operator","confidential_compute_attestation","custom_metric_autoscaler_operator_for_red_hat_openshift","dpu_kit_for_nvidia","exploit_intelligence","external_secrets_operator_for_red_hat_openshift","kernel_module_management_operator_for_red_hat_openshift","logging_subsystem_for_red_hat_openshift","logical_volume_manager_storage","machine_deletion_remediation_operator","migration_toolkit_for_containers","migration_toolkit_for_virtualization","multicluster_engine_for_kubernetes","node_healthcheck_operator","openshift_api_for_data_protection","openshift_developer_tools_and_services","openshift_lightspeed","openshift_pipelines","openshift_serverless","openshift_service_mesh 3","pen_drive_powered_by_red_hat_lightspeed","power_monitoring_for_red_hat_openshift","advanced_cluster_management_for_kubernetes 2","ai_inference_server","ansible_automation_platform 2","ceph_storage 9","certification_program_for_red_hat_enterprise_linux 9","developer_hub","edge_manager 1","hardened_images","openshift_ai_rhoai","openshift_container_platform 4","openshift_data_foundation 4","openshift_dev_spaces","openshift_dev_workspaces_operator","openshift_gitops","openshift_virtualization 4","openstack_platform 16.2"],"patched":["hardened_images"],"published":"2026-08-07","updated":"2026-09-10","sourceUpdated":"2026-09-10T20:41:33.140","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-71556","references":[{"url":"https://github.com/go-git/go-git/commit/008a78f2dd86f52544ddff8b8e8ddeecdf3f7aab","label":"security-advisories@github.com"},{"url":"https://github.com/go-git/go-git/commit/661d1c7f101d34e002a3cfcf8dbea5b7421d07ac","label":"security-advisories@github.com"},{"url":"https://github.com/go-git/go-git/releases/tag/v5.19.2","label":"security-advisories@github.com"},{"url":"https://github.com/go-git/go-git/releases/tag/v6.0.0-alpha.5","label":"security-advisories@github.com"},{"url":"https://github.com/go-git/go-git/security/advisories/GHSA-hc8v-wwc9-vgxm","label":"security-advisories@github.com"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-71556.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-71556"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2512562"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-71556"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-71556"},{"url":"https://access.redhat.com/errata/RHSA-2026:60793"},{"url":"https://access.redhat.com/errata/RHSA-2026:66208"},{"url":"https://access.redhat.com/errata/RHSA-2026:60646"},{"url":"https://github.com/advisories/GHSA-hc8v-wwc9-vgxm"},{"url":"https://access.redhat.com/errata/RHSA-2026:50953"},{"url":"https://access.redhat.com/errata/RHSA-2026:66363"},{"url":"https://access.redhat.com/errata/RHSA-2026:68334"},{"url":"https://access.redhat.com/errata/RHSA-2026:68335"},{"url":"https://access.redhat.com/errata/RHSA-2026:67538"},{"url":"https://access.redhat.com/errata/RHSA-2026:67540"},{"url":"https://access.redhat.com/errata/RHSA-2026:67539"},{"url":"https://access.redhat.com/errata/RHSA-2026:67541"},{"url":"https://access.redhat.com/errata/RHSA-2026:67542"},{"url":"https://access.redhat.com/errata/RHSA-2026:67543"},{"url":"https://access.redhat.com/errata/RHSA-2026:68044"},{"url":"https://access.redhat.com/errata/RHSA-2026:68253"},{"url":"https://access.redhat.com/errata/RHSA-2026:68006"},{"url":"https://access.redhat.com/errata/RHSA-2026:68254"},{"url":"https://access.redhat.com/errata/RHSA-2026:66421"}],"tags":["nvd","csaf","vex","red-hat","ghsa","go"],"epss":0.00357,"epssPercentile":0.29415,"aliases":["GHSA-hc8v-wwc9-vgxm"],"ecosystem":"go","ingestedAt":"2026-08-07T17:15:34.188Z","slug":"CVE-2026-71556","body":"## Overview\n\ngo-git is an extensible git implementation library written in pure Go. Prior to 5.19.2 and 6.0.0-alpha.5, worktree operations (including checkout, status, and add) resolve symbolic links inside the working tree without confining resolution to the worktree boundary, so a maliciously crafted repository containing a symlink can cause go-git to read from or write to files outside the intended working directory when the repository is cloned and its worktree operations are used. Versions 5.19.2 and 6.0.0-alpha.5.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Package advisory (CVE-2026-71556)\n\nAffected packages:\n\n- `github.com/go-git/go-git/v5 <= 5.19.1`\n- `github.com/go-git/go-git/v6 <= 6.0.0-alpha.4`\n\nPatched in:\n\n- `github.com/go-git/go-git/v5 5.19.2`\n- `github.com/go-git/go-git/v6 6.0.0-alpha.5`\n\nSource: https://github.com/advisories/GHSA-hc8v-wwc9-vgxm\n\n## Vendor advisories\n\n- **RHSA-2026:60793** · Red Hat · fixed in: Red Hat Hardened Images · released 2026-08-28 · [advisory](https://access.redhat.com/errata/RHSA-2026:60793)\n- **RHSA-2026:66208** · Red Hat · fixed in: Red Hat Hardened Images · released 2026-09-09 · [advisory](https://access.redhat.com/errata/RHSA-2026:66208)\n- **RHSA-2026:60646** · Red Hat · fixed in: Red Hat Hardened Images · released 2026-08-27 · [advisory](https://access.redhat.com/errata/RHSA-2026:60646)\n- **Red Hat VEX** · Important · affected: Assisted Installer for Red Hat OpenShift Container Platform 2, Builds for Red Hat OpenShift, Compliance Operator, Confidential Compute Attestation, DPU kit for NVIDIA, Exploit Intelligence, … · no fix planned: Assisted Installer for Red Hat OpenShift Container Platform 2, Exploit Intelligence, Multicluster Engine for Kubernetes, Red Hat Advanced Cluster Management for Kubernetes 2, … · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-71556.json)\n- **RHSA-2026:50953** · Red Hat · fixed in: Red Hat Hardened Images · released 2026-08-06 · [advisory](https://access.redhat.com/errata/RHSA-2026:50953)\n- **RHSA-2026:66363** · Red Hat · fixed in: external secrets operator for Red Hat OpenShift 1.2 · released 2026-09-10 · [advisory](https://access.redhat.com/errata/RHSA-2026:66363)\n- **RHSA-2026:68334** · Red Hat · fixed in: RHEM 1.1 for RHEL 10, RHEM 1.1 for RHEL 9 · released 2026-09-16 · [advisory](https://access.redhat.com/errata/RHSA-2026:68334)\n- **RHSA-2026:68335** · Red Hat · fixed in: RHEM 1.2 for RHEL 10, RHEM 1.2 for RHEL 9 · released 2026-09-16 · [advisory](https://access.redhat.com/errata/RHSA-2026:68335)\n- **RHSA-2026:67538** · Red Hat · fixed in: Red Hat Advanced Cluster Management for Kubernetes 2.11 · released 2026-09-15 · [advisory](https://access.redhat.com/errata/RHSA-2026:67538)\n- **RHSA-2026:67540** · Red Hat · fixed in: Red Hat Advanced Cluster Management for Kubernetes 2.13 · released 2026-09-15 · [advisory](https://access.redhat.com/errata/RHSA-2026:67540)\n- **RHSA-2026:67539** · Red Hat · fixed in: Red Hat Advanced Cluster Management for Kubernetes 2.14 · released 2026-09-15 · [advisory](https://access.redhat.com/errata/RHSA-2026:67539)\n- **RHSA-2026:67541** · Red Hat · fixed in: Red Hat Advanced Cluster Management for Kubernetes 2.15 · released 2026-09-15 · [advisory](https://access.redhat.com/errata/RHSA-2026:67541)\n- **RHSA-2026:67542** · Red Hat · fixed in: Red Hat Advanced Cluster Management for Kubernetes 2.16 · released 2026-09-15 · [advisory](https://access.redhat.com/errata/RHSA-2026:67542)\n- **RHSA-2026:67543** · Red Hat · fixed in: Red Hat Advanced Cluster Management for Kubernetes 2.17 · released 2026-09-15 · [advisory](https://access.redhat.com/errata/RHSA-2026:67543)\n- **RHSA-2026:68044** · Red Hat · fixed in: Red Hat Edge Manager 1.1 · released 2026-09-16 · [advisory](https://access.redhat.com/errata/RHSA-2026:68044)\n- **RHSA-2026:68253** · Red Hat · fixed in: Red Hat Edge Manager 1.1 · released 2026-09-16 · [advisory](https://access.redhat.com/errata/RHSA-2026:68253)\n- **RHSA-2026:68006** · Red Hat · fixed in: Red Hat Edge Manager 1.2 · released 2026-09-16 · [advisory](https://access.redhat.com/errata/RHSA-2026:68006)","depth":"twilight","depthScore":39,"depthScoreParts":{"impact":39.1,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}