gopkg.in/src-d/go-git.v4 vulnerabilities
CVEs whose affected-version data names the gopkg.in/src-d/go-git.v4 package (go). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
3 CVEsRSS
CVE-2025-21613NoneArgument Injection via the URL field in github.com/go-git/go-git
Argument Injection via the URL field in github.com/go-git/go-git
▾ Sunlitgo-git · github.com/go-git/go-git/v4EPSS 1.3%via OSV
CVE-2023-49569Critical· 9.8Maliciously crafted Git server replies can lead to path traversal and RCE on go-git clients
Maliciously crafted Git server replies can lead to path traversal and RCE on go-git clients
▾ Midnightgo-git · github.com/go-git/go-git/v5EPSS 1.5%via OSV
CVE-2023-49568High· 7.5Maliciously crafted Git server replies can cause DoS on go-git clients
Maliciously crafted Git server replies can cause DoS on go-git clients
▾ Twilightgo-git · github.com/go-git/go-git/v5EPSS 0.70%via OSV