Junglewise Threat Intelligence

CVE-2026-25934: GO-2026-4473 - Improper verification of data integrity values for .idx and .pack files in github.com/go-git/go-git

CVE-2026-25934 · Severity: low · CVSS 3.1 · Published 2026-02-19

Technologies: github.com/go-git/go-git/v4 (Go), github.com/go-git/go-git (Go), github.com/go-git/go-git/v5 (Go). Vendors: Go.

Executive brief

Improper verification of data integrity values for .idx and .pack files in github.com/go-git/go-git

Affected products

  • Go github.com/go-git/go-git/v4
  • Go github.com/go-git/go-git
  • Go github.com/go-git/go-git/v5

Related threats