Improper validation of integrity check value in go-git - CVE-2026-25934

 

Improper validation of integrity check value in go-git - CVE-2026-25934

Published: April 17, 2026


Vulnerability identifier: #VU126457
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-25934
CWE-ID: CWE-354
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause integrity issues by supplying corrupted repository data.

The vulnerability exists due to improper validation of integrity check values in .pack and .idx file handling when processing fetched packfiles and generated pack indexes. A remote attacker can provide corrupted repository data to cause integrity issues by making the application consume corrupted files and trigger unexpected errors.

User interaction is required for a client to fetch and process repository data.


Affected software

go-git
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
Public Cloud Module
openSUSE Leap
Ubuntu
terraform-provider-local
terraform-provider-tls
terraform-provider-random
terraform-provider-null
golang-github-go-git-go-git (Ubuntu package)

How to mitigate CVE-2026-25934

Install security update from vendor's website.

go-git - update to 5.16.5
terraform-provider-local - update to 2.0.0-150200.6.8.1
terraform-provider-tls - update to 3.0.0-150200.5.6.2
terraform-provider-random - update to 3.0.0-150200.6.6.2
terraform-provider-null - update to 3.0.0-150200.6.12.1
golang-github-go-git-go-git (Ubuntu package) - addressed in versions 5.4.2-3ubuntu0.1~esm1, 5.4.2-4ubuntu0.24.04.3+esm2

External References

Related Security Bulletins