CVE-2026-45022
ADVISORY - githubSummary
Impact
go-git may parse malformed Git objects in a way that differs from upstream Git. When commit or tag objects contain ambiguous or malformed headers, go-git’s decoded representation may expose values differently from how Git itself would interpret or reject the same object.
Additionally, go-git’s commit signing and verification logic operates over commit data reconstructed from go-git’s parsed representation rather than the original raw object bytes. As a result, go-git may sign or verify a commit payload that is not byte-for-byte equivalent to the object stored in the repository.
This can cause a signature to appear valid for a commit whose displayed or effective metadata differs from the object that was intended to be signed.
Patches
Users should upgrade to a patched version in order to mitigate this vulnerability. Versions prior to v5 are likely to be affected, users are recommended to upgrade to a supported go-git version.
Credit
Thanks to @bugbunny-research (https://bugbunny.ai/) for reporting this to sigstore/gitsign, and to @wlynch, @patzielinski and @adityasaky for coordinating the disclosure with the go-git project. :bow: :1st_place_medal:
Thanks to @wayphinder for reporting this to the go-git project. :bow:
GitHub
CVSS SCORE
7highChainguard
CGA-8x53-pqv6-wqhw
-
minimos
MINI-2945-rqgx-7j7m
-
minimos
MINI-3pcr-9m8g-c6cq
-
minimos
MINI-432f-vrwf-gpcp
-
minimos
MINI-56f9-r345-8g9v
-
minimos
MINI-59jc-23xj-q9gf
-
minimos
MINI-5fw6-hxg6-62cg
-
minimos
MINI-5w74-jj2v-474g
-
minimos
MINI-5wxv-48r4-53v5
-
minimos
MINI-8427-w35w-p75x
-
minimos
MINI-8rvf-5pc5-x5pj
-
minimos
MINI-93pq-qcvf-4gf4
-
minimos
MINI-95fq-pg9m-68px
-
minimos
MINI-9c7x-4xx5-g5p6
-
minimos
MINI-9gcp-5pf5-j3xq
-
minimos
MINI-9mmf-wxw4-rqfw
-
minimos
MINI-c9wr-55r8-6xgg
-
minimos
MINI-fq47-mx76-j4g9
-
minimos
MINI-fvc4-hf5h-38h3
-
minimos
MINI-fvw9-jfq3-xwvq
-
minimos
MINI-h86g-g7mj-vjvr
-
minimos
MINI-hc37-5c89-6g7v
-
minimos
MINI-hw6w-248v-mfvm
-
minimos
MINI-mhgx-5w95-pj5v
-
minimos
MINI-mj8q-r53c-h4w7
-
minimos
MINI-mw87-vp7g-cxp2
-
minimos
MINI-pjmm-j7x4-jhr9
-
minimos
MINI-pw74-wh35-5mrg
-
minimos
MINI-q782-wg8x-r5qx
-
minimos
MINI-qfw4-93x7-p459
-
minimos
MINI-r28f-g489-484q
-
minimos
MINI-r3jj-9rr2-77wv
-
minimos
MINI-r6qh-c4px-w4x6
-
minimos
MINI-r86c-6r24-5jpr
-
minimos
MINI-rr29-98m4-63r4
-
minimos
MINI-vqx4-g3m9-vpfj
-
minimos
MINI-vwp8-fm9j-69qj
-
minimos
MINI-w77p-2r43-qv96
-
minimos
MINI-wfjj-3m87-pq9m
-
minimos
MINI-wvj8-874x-rmwp
-
minimos
MINI-x334-977m-754q
-