Search CVE reports


Toggle filters

1 – 10 of 1587 results


CVE-2026-44740

Medium priority
Needs evaluation

Billy is an interface filesystem abstraction for Go. Prior to versions 5.9.0 and 6.0.0-alpha.1, multiple components may improperly handle crafted or malformed input, resulting in panics, infinite loops, uncontrolled recursion, or...

2 affected packages

golang-github-go-git-go-billy, golang-github-go-git-go-billy-v6

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-github-go-git-go-billy Needs evaluation Needs evaluation Needs evaluation
golang-github-go-git-go-billy-v6 Not in release Not in release Not in release
Show less packages

CVE-2026-48501

Medium priority
Needs evaluation

GitHub CLI (gh) is GitHub’s official command line tool. Prior to 2.93.0, GitHub CLI incorrectly includes authorization header in API requests to TUF repository mirrors via gh attestation, gh release verify, and gh...

2 affected packages

golang-github-cli-go-gh, golang-github-cli-go-gh-v2

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-github-cli-go-gh Needs evaluation Needs evaluation Not in release
golang-github-cli-go-gh-v2 Needs evaluation Needs evaluation Not in release
Show less packages

CVE-2026-2601

Medium priority

Not in release

GitLab has remediated an issue in GitLab EE affecting all versions from 11.5 before 18.10.7, 18.11 before 18.11.4, and 19.0 before 19.0.1 that under certain conditions could have allowed an authenticated user with developer-role...

1 affected package

gitlab

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release Not in release Not in release
Show less packages

CVE-2026-1402

Medium priority

Not in release

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.1 before 18.10.7, 18.11 before 18.11.4, and 19.0 before 19.0.1 that under certain conditions could have allowed an authenticated user to cause denial of...

1 affected package

gitlab

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release Not in release Not in release
Show less packages

CVE-2026-44973

Medium priority
Needs evaluation

Billy is an interface filesystem abstraction for Go. Prior to 5.9.0, multiple path traversal issues exist across different components of go-billy. Insufficient path sanitization and boundary enforcement may allow crafted paths...

1 affected package

golang-github-go-git-go-billy

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-github-go-git-go-billy Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-45571

Medium priority
Needs evaluation

go-git is an extensible git implementation library written in pure Go. Prior to 5.19.1 and 6.0.0-alpha.4, a path validation issue in go-git could allow crafted repository data to affect files outside the intended checkout target,...

1 affected package

golang-github-go-git-go-git

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-github-go-git-go-git Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-45570

Medium priority
Needs evaluation

go-git is an extensible git implementation library written in pure Go. Prior to 5.19.1 and 6.0.0-alpha.4, go-git's SSH transport constructs the remote exec command by wrapping the repository path in single quotes without escaping...

1 affected package

golang-github-go-git-go-git

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-github-go-git-go-git Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-45022

Medium priority
Needs evaluation

go-git is an extensible git implementation library written in pure Go. Prior to 5.19.0 and 6.0.0-alpha.3, go-git may parse malformed Git objects in a way that differs from upstream Git. When commit or tag objects contain ambiguous...

1 affected package

golang-github-go-git-go-git

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-github-go-git-go-git Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-44310

Medium priority
Needs evaluation

Gitsign is a keyless Sigstore to signing tool for Git commits with your a GitHub / OIDC identity. From 0.4.0 to before 0.15.0, CertVerifier.Verify() in pkg/git/verifier.go unconditionally dereferences certs[0]...

1 affected package

gitsign

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitsign Needs evaluation Not in release Not in release
Show less packages

CVE-2026-44309

Medium priority
Needs evaluation

Gitsign is a keyless Sigstore to signing tool for Git commits with your a GitHub / OIDC identity. Prior to 0.16.0, gitsign verify and gitsign verify-tag re-encode commit/tag objects through go-git's EncodeWithoutSignature before...

1 affected package

gitsign

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitsign Needs evaluation Not in release Not in release
Show less packages