CVE-2026-33762Low· 2.8▾ Sunlitgo-git is an extensible git implementation library written in pure Go. Prior to version 5.17.1, go-git’s index decoder for format version 4 fails to validate the path name prefix length before applying it to the previously decoded path n…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 15.4 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 24.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.2%
go-git is an extensible git implementation library written in pure Go. Prior to version 5.17.1, go-git’s index decoder for format version 4 fails to validate the path name prefix length before applying it to the previously decoded path name. A maliciously crafted index file can trigger an out-of-bounds slice operation, resulting in a runtime panic during normal index parsing. This issue only affects Git index format version 4. Earlier formats (go-git supports only v2 and v3) are not vulnerable to this issue. This issue has been patched in version 5.17.1.
go-git < 5.17.1Upgrade past the affected range:
go-git 5.17.1Connected by shared product, vendor, weakness, or advisory.
CVE-2026-34165Medium· 5.0go-git is an extensible git implementation library written in pure Go
CVE-2023-2008High· 8.2A flaw was found in the Linux kernel's udmabuf device driver, within a fault handler
CVE-2026-62866Medium· 6.2Dasel is a command-line tool and library for querying, modifying, and transforming data structures
CVE-2026-65653High· 8.7github.com/temporalio/tchannel-go did not reject TChannel call fragments containing checksum metadata but no length-prefixed argument chunks
CVE-2026-65652High· 8.7github.com/temporalio/tchannel-go did not validate the one-byte checksum-type field in inbound TChannel call frames
CVE-2026-16651High· 8.7temporalio/sqlparser can panic when Parse, ParseStrictDDL, or ParseNext processes a MySQL version comment whose contents are empty or consist only of one to five decimal digits