Junglewise Threat Intelligence

CVE-2026-33762: go-git out-of-bounds read in Git index v4 decoder

CVE-2026-33762 · Severity: low · CVSS 3.1 · Published 2026-03-31

Technologies: github.com/go-git/go-git/v4 (Go), Go-Git Project Go-Git, github.com/go-git/go-git (Go), github.com/go-git/go-git/v5 (Go). Vendors: Go.

Executive brief

go-git is a software library used by developers to build Git-related features into their applications. A flaw in how the library reads specific Git index files allows a specially crafted file to crash the application. This could lead to a denial-of-service where the application stops responding or shuts down unexpectedly when processing a malicious repository.

Technical details

A vulnerability exists in go-git's index decoder for Git index format version 4 (CWE-129). The decoder fails to validate the path name prefix length before applying it to previously decoded path names during delta compression processing. An attacker with the ability to provide a maliciously crafted .git/index file can trigger an out-of-bounds slice operation. This results in a Go runtime panic, leading to a denial-of-service (DoS) if the application does not implement panic recovery. The issue is specific to index format v4; versions v2 and v3 are unaffected. The vulnerability is addressed in version 5.17.1.

Affected products

  • go-git project go-git < 5.17.1

Timeline

  • 2026-03-29: patched: Version 5.17.1 released
  • 2026-03-31: advisory: GitHub Security Advisory published
  • 2026-03-31: disclosed: CVE-2026-33762 published

References

Related threats