---
id: CVE-2026-25934
title: >-
  go-git/go-git: go-git: Data integrity issue due to improper verification of
  pack and index files (CVE-2026-25934)
summary: >-
  A flaw was found in go-git, a library for Git implementation in Go. This
  vulnerability allows a remote attacker to provide specially crafted Git pack
  or index files that are not properly verified for data integrity. Successful
  exploitation…
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'
cvssSource: vendor
cwe: CWE-354
vendor: Red Hat
product: Red Hat Openshift Data Foundation 4.22
affected:
  - assisted_installer_for_red_hat_openshift_container_platform 2
  - builds_for_red_hat_openshift
  - confidential_compute_attestation
  - external_secrets_operator_for_red_hat_openshift
  - kernel_module_management_operator_for_red_hat_openshift
  - logging_subsystem_for_red_hat_openshift
  - machine_deletion_remediation_operator
  - migration_toolkit_for_containers
  - migration_toolkit_for_virtualization
  - multicluster_engine_for_kubernetes
  - network_observability_operator
  - node_healthcheck_operator
  - openshift_api_for_data_protection
  - openshift_developer_tools_and_services
  - openshift_pipelines
  - openshift_serverless
  - openshift_service_mesh 2
  - openshift_service_mesh 3
  - pen_drive_powered_by_red_hat_lightspeed
  - power_monitoring_for_red_hat_openshift
  - advanced_cluster_management_for_kubernetes 2
  - advanced_cluster_security 4
  - ansible_automation_platform 2
  - build_of_kueue
  - edge_manager 1
  - enterprise_linux 8
  - enterprise_linux 9
  - openshift_ai_rhoai
  - openshift_container_platform 4
  - openshift_dev_workspaces_operator
  - openshift_for_windows_containers
  - openshift_gitops
  - openshift_virtualization 4
  - openstack_platform 16.2
  - openstack_platform 17.1
  - openstack_platform 18.0
  - trusted_artifact_signer
  - openshift_data_foundation 4.22
patched:
  - openshift_data_foundation 4.22
published: '2026-02-09'
updated: '2026-09-21'
sourceUpdated: '2026-09-21T17:22:37+00:00'
source: CSAF
sourceUrl: 'https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-25934.json'
references:
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-25934.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-25934'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2438332'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-25934'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-25934'
  - url: 'https://github.com/go-git/go-git/releases/tag/v5.16.5'
  - url: 'https://github.com/go-git/go-git/security/advisories/GHSA-37cx-329c-33x3'
  - url: 'https://access.redhat.com/errata/RHSA-2026:37387'
  - url: 'https://github.com/go-git/go-git'
tags:
  - csaf
  - vex
  - red-hat
  - osv
  - go
epss: 0.00153
epssPercentile: 0.03698
aliases:
  - GHSA-37cx-329c-33x3
  - GO-2026-4473
ecosystem: go
ingestedAt: '2026-09-12T03:13:01.748Z'
---

## Overview

A flaw was found in go-git, a library for Git implementation in Go. This vulnerability allows a remote attacker to provide specially crafted Git pack or index files that are not properly verified for data integrity. Successful exploitation could lead to the go-git library processing corrupted data, which may result in unexpected application errors such as 'object not found'.

## Vendor advisories

- **RHSA-2026:37387** · Red Hat · fixed in: Red Hat Openshift Data Foundation 4.22 · released 2026-07-09 · [advisory](https://access.redhat.com/errata/RHSA-2026:37387)
- **Red Hat VEX** · Moderate · affected: Assisted Installer for Red Hat OpenShift Container Platform 2, Builds for Red Hat OpenShift, Confidential Compute Attestation, External Secrets Operator for Red Hat OpenShift, Kernel Module Management Operator for Red Hat Openshift, Logging Subsystem for Red Hat OpenShift, … · no fix planned: Assisted Installer for Red Hat OpenShift Container Platform 2, Builds for Red Hat OpenShift, Confidential Compute Attestation, External Secrets Operator for Red Hat OpenShift, … · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-25934.json)

**go-git/go-git: go-git: Data integrity issue due to improper verification of pack and index files** — rated Moderate by Red Hat. Released 2026-02-09, updated 2026-09-21.

Affected:

- Assisted Installer for Red Hat OpenShift Container Platform 2
- Builds for Red Hat OpenShift
- Confidential Compute Attestation
- External Secrets Operator for Red Hat OpenShift
- Kernel Module Management Operator for Red Hat Openshift
- Logging Subsystem for Red Hat OpenShift
- Machine Deletion Remediation Operator
- Migration Toolkit for Containers
- Migration Toolkit for Virtualization
- Multicluster Engine for Kubernetes
- Network Observability Operator
- Node HealthCheck Operator
- OpenShift API for Data Protection
- OpenShift Developer Tools and Services
- OpenShift Pipelines
- OpenShift Serverless
- OpenShift Service Mesh 2
- OpenShift Service Mesh 3
- Pen Drive Powered by Red Hat Lightspeed
- Power monitoring for Red Hat OpenShift
- Red Hat Advanced Cluster Management for Kubernetes 2
- Red Hat Advanced Cluster Security 4
- Red Hat Ansible Automation Platform 2
- Red Hat Build of Kueue
- Red Hat Edge Manager 1
- Red Hat Enterprise Linux 8
- Red Hat Enterprise Linux 9
- Red Hat OpenShift AI (RHOAI)
- Red Hat OpenShift Container Platform 4
- Red Hat OpenShift Dev Workspaces Operator
- Red Hat OpenShift for Windows Containers
- Red Hat OpenShift GitOps
- Red Hat OpenShift Virtualization 4
- Red Hat OpenStack Platform 16.2
- Red Hat OpenStack Platform 17.1
- Red Hat OpenStack Platform 18.0
- Red Hat Trusted Artifact Signer

Fixed:

- Red Hat Openshift Data Foundation 4.22

No fix planned:

- Assisted Installer for Red Hat OpenShift Container Platform 2
- Builds for Red Hat OpenShift
- Confidential Compute Attestation
- External Secrets Operator for Red Hat OpenShift
- Kernel Module Management Operator for Red Hat Openshift
- Logging Subsystem for Red Hat OpenShift
- Machine Deletion Remediation Operator
- Migration Toolkit for Containers
- Migration Toolkit for Virtualization
- Multicluster Engine for Kubernetes
- Network Observability Operator
- Node HealthCheck Operator
- OpenShift API for Data Protection
- OpenShift Developer Tools and Services
- OpenShift Pipelines
- OpenShift Serverless
- OpenShift Service Mesh 2
- OpenShift Service Mesh 3
- Pen Drive Powered by Red Hat Lightspeed
- Power monitoring for Red Hat OpenShift
- Red Hat Advanced Cluster Management for Kubernetes 2
- Red Hat Advanced Cluster Security 4
- Red Hat Ansible Automation Platform 2
- Red Hat Build of Kueue
- Red Hat Edge Manager 1
- Red Hat Enterprise Linux 8
- Red Hat Enterprise Linux 9
- Red Hat OpenShift AI (RHOAI)
- Red Hat OpenShift Container Platform 4
- Red Hat OpenShift Dev Workspaces Operator
- Red Hat OpenShift for Windows Containers
- Red Hat OpenShift GitOps
- Red Hat OpenShift Virtualization 4
- Red Hat OpenStack Platform 16.2
- Red Hat OpenStack Platform 17.1
- Red Hat OpenStack Platform 18.0
- Red Hat Trusted Artifact Signer

Not affected:

- Red Hat Openshift Data Foundation 4.22

## Remediation

Before applying this update, make sure all previously released errata
relevant to your system have been applied.

For details on how to apply this update, refer to:

https://docs.redhat.com/en/documentation/red_hat_openshift_data_foundation/4.22/html/updating_openshift_data_foundation/updating-ocs-to-odf_rhodf https://access.redhat.com/errata/RHSA-2026:37387

## Package advisory (CVE-2026-25934)

Affected packages:

- `github.com/go-git/go-git/v5 < 5.16.5`

Patched in:

- `github.com/go-git/go-git/v5 5.16.5`

Source: https://osv.dev/vulnerability/GHSA-37cx-329c-33x3
