Junglewise Threat Intelligence

CVE-2026-41506: go-git credential leak via cross-host redirect in smart HTTP transport

CVE-2026-41506 · Severity: medium · CVSS 4.7 · Published 2026-05-08

Technologies: github.com/go-git/go-git/v5 (Go), github.com/go-git/go-git/v6 (Go), Go-Git. Vendors: Go-Git, Go.

Executive brief

go-git is a library used by developers to integrate Git functionality into Go applications. A security flaw allows sensitive login credentials to be leaked to unauthorized third-party servers when the library follows a web redirect during repository operations. This could allow an attacker who controls a malicious Git server to steal user credentials and gain unauthorized access to other private repositories or resources.

Technical details

A credential leak vulnerability exists in go-git's smart-HTTP transport implementation. When a remote repository responds to an initial /info/refs request with a redirect to a different host, go-git updates the session endpoint to the new location but reuses the original Authorization headers for subsequent requests. This allows an attacker-controlled server to capture credentials intended for the original host. The vulnerability is rooted in insufficient protection of credentials during cross-host redirects (CWE-522). The issue is addressed in versions 5.18.0 and 6.0.0-alpha.2 by introducing a configurable followRedirects policy that defaults to 'initial' only, matching canonical Git behavior.

Affected products

  • go-git go-git/v5 < 5.18.0
  • go-git go-git/v6 < 6.0.0-alpha.2

Timeline

  • 2026-04-16: patched: Versions 5.18.0 and 6.0.0-alpha.2 released
  • 2026-05-08: disclosed: Initial CVE publication
  • 2026-05-08: advisory: GitHub Security Advisory published

References

Related threats