Known vulnerabilities in git-lfs (Red Hat package)

Software CPE: cpe:2.3:o:red_hat:git-lfs_redhat_package:*:*:*:*:*:red_hat_enterprise_linux:*:*
Total vulnerabilities: 30
Public exploits: 1
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting git-lfs (Red Hat package) git-lfs (Red Hat package) is affected by 30 known vulnerabilities: 2 high, 23 medium, 5 low Critical High Medium Low

Vulnerabilities (30)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU140611 - Double Free
CVE-2026-33811
CWE-415 Medium
No
No
3.4.1-12.el8_10, 3.7.1-4.el9_8.2, 3.7.1-5.el10_2.6 31.07.2026 SB2026073126
SB20260731121
SB20260731123
and 13 more
#VU140607 - Time-of-check Time-of-use (TOCTOU) Race Condition
CVE-2026-32282
CWE-367 Low
No
No
3.4.1-10.el8_10, 3.6.1-2.el9_6.4, 3.6.1-2.el10_0.4, 3.6.1-8.el9_7.1 31.07.2026 SB2026073125
SB2026073160
SB2026073161
and 50 more
#VU140599 - Resource exhaustion
CVE-2026-32280
CWE-400 Medium
No
No
3.4.1-10.el8_10, 3.6.1-2.el9_6.4, 3.6.1-2.el10_0.4, 3.6.1-8.el9_7.1 31.07.2026 SB2026073125
SB2026073160
SB2026073161
and 70 more
#VU136680 - Dependency on Vulnerable Third-Party Component
CVE-2026-32283
CWE-1395 Medium
No
No
3.4.1-10.el8_10, 3.6.1-2.el9_6.4, 3.6.1-2.el10_0.4, 3.6.1-8.el9_7.1 02.07.2026 SB2026070218
SB2026070239
SB2026070240
and 61 more
#VU124118 - Improper input validation
CVE-2026-25679
CWE-20 Medium
No
No
2.13.3-3.el8_4.5, 2.13.3-3.el8_6.7, 2.13.3-5.el9_0.7, 3.2.0-2.el9_2.6, 3.4.1-4.el9_4.5, 3.4.1-10.el8_10, 3.6.1-2.el9_6.3, 3.6.1-2.el10_0.3, 3.6.1-8.el9_7 19.03.2026 SB2026031903
SB2026031904
SB2026031905
and 134 more
#VU124034 - Resource exhaustion
CVE-2025-61726
CWE-400 Medium
No
No
2.13.3-3.el8_4.4, 2.13.3-5.el9_0.6, 3.2.0-2.el8_8.6, 3.2.0-2.el9_2.5, 3.4.1-4.el9_4.4, 3.6.1-2.el9_6.2, 3.6.1-2.el10_0.2, 3.6.1-7.el9_7, 3.6.1-7.el10_1 16.03.2026 SB2026031636
SB2026031637
SB2026031638
and 143 more
#VU123129 - Improper Certificate Validation
CVE-2025-68121
CWE-295 High
No
No
3.6.1-2.el9_6.2, 3.6.1-2.el10_0.2, 3.6.1-7.el9_7, 3.6.1-7.el10_1 23.02.2026 SB2026022333
SB2026030334
SB2026030343
and 116 more
#VU119235 - Resource exhaustion
CVE-2025-61729
CWE-400 Medium
No
No
2.13.3-3.el8_4.4, 2.13.3-5.el9_0.6, 3.2.0-2.el8_8.6, 3.2.0-2.el9_2.5, 3.4.1-4.el9_4.4, 3.4.1-7.el8_10, 3.6.1-2.el9_6.2, 3.6.1-2.el10_0.2, 3.6.1-7.el9_7, 3.6.1-7.el10_1 06.12.2025 SB2025120604
SB20251210172
SB20251210173
and 146 more
#VU118253 - Improper Link Resolution Before File Access ('Link Following')
CVE-2025-26625
CWE-59 High
No
No
2.13.3-3.el8_4.3, 2.13.3-3.el8_6.5, 2.13.3-5.el9_0.5, 3.2.0-2.el8_8.5, 3.2.0-2.el9_2.4, 3.4.1-4.el9_4.3, 3.4.1-6.el8_10, 3.6.1-2.el9_6.1, 3.6.1-2.el10_0.1, 3.6.1-4.el9_7, 3.6.1-4.el10_1 11.11.2025 SB2025111128
SB2025111129
SB2025111130
and 20 more
#VU107019 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2025-22871
CWE-444 Medium
No
No
2.13.3-3.el8_6.4, 2.13.3-5.el9_0.4, 3.2.0-2.el8_8.4, 3.2.0-2.el9_2.3 05.04.2025 SB2025040507
SB2025040508
SB2025040739
and 109 more
#VU102873 - Improper input validation
CVE-2024-53263
CWE-20 Medium
No
No
2.13.3-3.el8_4.1, 2.13.3-3.el8_6.3, 2.13.3-5.el9_0.3, 3.2.0-2.el8_8.3, 3.2.0-2.el9_2.2, 3.4.1-4.el8_10, 3.4.1-4.el9_4.1, 3.4.1-4.el9_5 16.01.2025 SB2025011645
SB2025011648
SB2025011649
and 15 more
#VU97216 - Resource exhaustion
CVE-2024-34156
CWE-400 Medium
No
No
2.11.0-2.el8_4.3, 2.13.3-3.el8_6.2, 2.13.3-5.el9_0.2, 3.2.0-2.el8_8.2, 3.2.0-2.el9_2.1, 3.4.1-3.el8_10, 3.4.1-4.el9_4 12.09.2024 SB2024091261
SB2024091264
SB2024091265
and 143 more
#VU88184 - Resource exhaustion
CVE-2023-45288
CWE-400 Medium
Available
No
2.11.0-2.el8_4.2, 2.13.3-3.el8_6.1, 2.13.3-5.el9_0.1, 3.2.0-1.el9_2, 3.2.0-2.el8_8.1, 3.2.0-2.el9_3, 3.2.0-3.el8_9, 3.4.1-2.el8_10, 3.4.1-2.el9_4 05.04.2024 SB2024040533
SB2024040549
SB2024040551
and 189 more
#VU87198 - Exposure of sensitive information to an unauthorized actor
CVE-2023-45289
CWE-200 Low
No
No
3.4.1-2.el8_10, 3.4.1-2.el9_4 07.03.2024 SB2024030734
SB2024030750
SB2024030752
and 54 more
#VU87197 - Resource exhaustion
CVE-2023-45290
CWE-400 Medium
No
No
3.4.1-2.el8_10, 3.4.1-2.el9_4 07.03.2024 SB2024030734
SB2024030750
SB2024030752
and 101 more
#VU87196 - Error Handling
CVE-2024-24783
CWE-388 Medium
No
No
3.4.1-2.el8_10, 3.4.1-2.el9_4 07.03.2024 SB2024030734
SB2024030750
SB2024030752
and 81 more
#VU68389 - Improper input validation
CVE-2022-2880
CWE-20 Medium
No
No
3.2.0-1.el9, 3.2.0-2.el8 18.10.2022 SB2022101833
SB2022101834
SB2022102005
and 94 more
#VU11620 - Exposure of sensitive information to an unauthorized actor
CVE-2017-1765
CWE-200 Low
No
No
3.2.0-2.el8_8.1 08.04.2018 SB2018032404
SB2024072620
#VU11619 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2018-1384
CWE-79 Low
No
No
3.2.0-2.el8_8.1 08.04.2018 SB2018032404
SB2024072620
#VU11618 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2017-1767
CWE-79 Low
No
No
3.2.0-2.el8_8.1 04.04.2018 SB2018032404
SB2024072620


Showing elements 1 - 20 out of 30