Integer underflow in go-git - CVE-2026-34165
Published: April 17, 2026
Vulnerability identifier: #VU126455
CSH Severity: Medium
CVSS v4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-34165
CWE-ID: CWE-191
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to integer underflow in .idx file processing when parsing a crafted .idx file. A local user can create or alter an .idx file in the local repository's .git directory to cause a denial of service.
User interaction is required.
Affected software
go-git
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
Fedora
trivy
tailscale
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
Fedora
trivy
tailscale
How to mitigate CVE-2026-34165
Install security update from vendor's website.
go-git - update to 5.17.1
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 5.3.1 Patch 5
trivy - update to 0.69.3-1.fc44
tailscale - addressed in versions 1.98.4-1.fc44, 1.98.4-1.fc45
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 5.3.1 Patch 5
trivy - update to 0.69.3-1.fc44
tailscale - addressed in versions 1.98.4-1.fc44, 1.98.4-1.fc45