CVE-2026-41506
ADVISORY - githubSummary
Impact
go-git may leak HTTP authentication credentials when following redirects during smart-HTTP clone and fetch operations.
If a remote repository responds to the initial /info/refs request with a redirect to a different host, go-git updates the session endpoint to the redirected location and reuses the original authentication for subsequent requests. This can result in the credentials (e.g. Authorization headers) being sent to an unintended host.
An attacker controlling or influencing the redirect target can capture these credentials and potentially reuse them to access the victim’s repositories or other resources, depending on the scope of the credential.
Clients using go-git exclusively with trusted remotes (for example, GitHub or GitLab), and over a secure HTTPS connection, are not affected by this issue. The risk arises when interacting with untrusted or misconfigured Git servers, or when using unsecured HTTP connections, which is not recommended. Such configurations also expose clients to a broader class of security risks beyond this issue, including credential interception and tampering of repository data.
Patches
Users should upgrade to v5.18.0, or v6.0.0-alpha.2, in order to mitigate this vulnerability. Versions prior to v5 are likely to be affected, users are recommended to upgrade to a supported go-git version.
The patched versions add support for configuring followRedirects. In line with upstream behaviour, the default is now initial, while users can opt into FollowRedirects or NoFollowRedirects programmatically.
Credit
Thanks to the 3 separate reports from @celinke97, @N0zoM1z0 and @AyushParkara. Thanks for finding and reporting this issue privately to the go-git project. :bow:
Common Weakness Enumeration (CWE)
Insufficiently Protected Credentials
Insufficiently Protected Credentials
GitHub
2.8
CVSS SCORE
4.7medium| Package | Type | OS Name | OS Version | Affected Ranges | Fix Versions |
|---|---|---|---|---|---|
| github.com/go-git/go-git/v5 | golang | - | - | <=5.17.2 | 5.18.0 |
| github.com/go-git/go-git/v5 | golang | - | - | <0.0.0-20260416212733-ea3e7ec9dfc5 | 0.0.0-20260416212733-ea3e7ec9dfc5 |
| github.com/go-git/go-git/v6 | golang | - | - | <=6.0.0-alpha.1 | 6.0.0-alpha.2 |
| github.com/go-git/go-git/v6 | golang | - | - | <0.0.0-20260416203929-137874facf92 | 0.0.0-20260416203929-137874facf92 |
CVSS:3 Severity and metrics
The CVSS metrics represent different qualitative aspects of a vulnerability that impact the overall score, as defined by the CVSS Specification.
The vulnerable component is bound to the network stack, but the attack is limited at the protocol level to a logically adjacent topology. This can mean an attack must be launched from the same shared physical (e.g., Bluetooth or IEEE 802.11) or logical (e.g., local IP subnet) network, or from within a secure or otherwise limited administrative domain (e.g., MPLS, secure VPN to an administrative network zone). One example of an Adjacent attack would be an ARP (IPv4) or neighbor discovery (IPv6) flood leading to a denial of service on the local LAN segment (e.g., CVE-2013-6014).
Specialized access conditions or extenuating circumstances do not exist. An attacker can expect repeatable success when attacking the vulnerable component.
The attacker is unauthorized prior to attack, and therefore does not require any access to settings or files of the vulnerable system to carry out an attack.
Successful exploitation of this vulnerability requires a user to take some action before the vulnerability can be exploited. For example, a successful exploit may only be possible during the installation of an application by a system administrator.
An exploited vulnerability can affect resources beyond the security scope managed by the security authority of the vulnerable component. In this case, the vulnerable component and the impacted component are different and managed by different security authorities.
There is some loss of confidentiality. Access to some restricted information is obtained, but the attacker does not have control over what information is obtained, or the amount or kind of loss is limited. The information disclosure does not cause a direct, serious loss to the impacted component.
There is no loss of trust or accuracy within the impacted component.
There is no impact to availability within the impacted component.
NIST
2.8
CVSS SCORE
4.7mediumDebian
-
Ubuntu
2.8
CVSS SCORE
7.4mediumGoLang
-
Amazon
-
CVSS SCORE
N/AmediumAmazon
-
CVSS SCORE
N/AhighAmazon
-
CVSS SCORE
N/AmediumAmazon
-
CVSS SCORE
N/AhighChainguard
CGA-fwfh-x7w7-2jp6
-
minimos
MINI-2mv6-h7gx-9g4v
-
minimos
MINI-2p9f-px83-m3cg
-
minimos
MINI-2vwc-q2vh-77h6
-
minimos
MINI-3hhf-5xvv-2vpj
-
minimos
MINI-3pcq-xh3r-4f7w
-
minimos
MINI-3v8g-vjhm-5xpm
-
minimos
MINI-3wgj-vfq5-2m2h
-
minimos
MINI-4cch-xw7f-vqjm
-
minimos
MINI-4hg8-4m5w-j972
-
minimos
MINI-55wg-q942-vqv9
-
minimos
MINI-58pr-jwmr-hwpf
-
minimos
MINI-5j34-cjgg-fq98
-
minimos
MINI-5q57-28fg-7mr7
-
minimos
MINI-5r96-f7xg-7hj6
-
minimos
MINI-5v2c-994x-45p4
-
minimos
MINI-63qv-6pgp-vcmr
-
minimos
MINI-66ff-5hcw-qvgc
-
minimos
MINI-6wc9-c3cx-h543
-
minimos
MINI-6xgq-wg82-4wc4
-
minimos
MINI-7552-65q4-fgrg
-
minimos
MINI-76pj-rhhj-rmjg
-
minimos
MINI-76pm-87p4-4p7g
-
minimos
MINI-787f-58cw-8482
-
minimos
MINI-7v3q-m42m-xgpp
-
minimos
MINI-826g-x2gc-q63g
-
minimos
MINI-893w-7v3p-922v
-
minimos
MINI-8phh-88cv-fff7
-
minimos
MINI-92gh-c7gx-wjrv
-
minimos
MINI-93m2-48c5-qvph
-
minimos
MINI-95fh-4rx6-2hxh
-
minimos
MINI-98wj-cpjj-568f
-
minimos
MINI-9c5j-5w47-5whx
-
minimos
MINI-9gq2-m3qj-g976
-
minimos
MINI-c34j-ghrg-9qcq
-
minimos
MINI-cp5m-6m68-xx96
-
minimos
MINI-f5q6-gg6h-7p5v
-
minimos
MINI-ffmv-349v-phqq
-
minimos
MINI-fmwj-8qrr-6m6c
-
minimos
MINI-fq5p-5g3f-9crj
-
minimos
MINI-fqrg-ggm9-3vr4
-
minimos
MINI-g2p9-xvfm-m6jq
-
minimos
MINI-gc58-68m7-p4q8
-
minimos
MINI-grxm-27cw-f592
-
minimos
MINI-hwfp-7q2j-c5r6
-
minimos
MINI-j522-q6rr-43f8
-
minimos
MINI-jwx6-8769-gg3w
-
minimos
MINI-m2hc-wmwh-qw33
-
minimos
MINI-m6wg-22m7-qpjq
-
minimos
MINI-m89v-pg2x-8h6g
-
minimos
MINI-mf28-j95x-6c5v
-
minimos
MINI-mvgr-2322-5hg4
-
minimos
MINI-mw5h-v3qh-66fg
-
minimos
MINI-p39w-8vr6-fhxx
-
minimos
MINI-p93p-64hr-89gm
-
minimos
MINI-ph45-3wqh-5mg9
-
minimos
MINI-phjx-r5rw-5cr7
-
minimos
MINI-pp5m-pxjw-pgp7
-
minimos
MINI-pxmr-fc9r-546p
-
minimos
MINI-qgmp-wj46-3v6j
-
minimos
MINI-qmqq-4mrg-3m63
-
minimos
MINI-qwcr-8cw5-98w8
-
minimos
MINI-r4m2-6xmx-fpxv
-
minimos
MINI-rjj2-mgg9-55qh
-
minimos
MINI-rp76-988p-87h4
-
minimos
MINI-v7rx-xv49-v62j
-
minimos
MINI-vf75-3r4q-ppfw
-
minimos
MINI-vfg2-j234-8p2f
-
minimos
MINI-vrcc-67qj-6pp4
-
minimos
MINI-w395-3hgw-pmjc
-
minimos
MINI-wcgf-34pv-7h44
-
minimos
MINI-wh2v-p9mw-47jr
-
minimos
MINI-wqf5-9rfw-8wmx
-
minimos
MINI-wrpj-8mgr-q8w3
-
minimos
MINI-x9vh-p7f7-v5cq
-
minimos
MINI-xf5g-wpv8-pmq9
-
minimos
MINI-xgw7-fcq2-5gcg
-
minimos
MINI-xxj3-rjrx-7j54
-