Path traversal in go-git - CVE-2026-71557
Published: July 31, 2026 / Updated: August 8, 2026
Vulnerability details
The vulnerability allows a remote user to modify files outside the intended reference storage.
The vulnerability exists due to path traversal in the `storage/filesystem` package `dotgit` reference storage when processing attacker-controlled reference names during clone or fetch operations. A remote user can advertise a specially crafted reference name to modify files outside the intended reference storage.
This affects filesystem-backed repositories, while instances using only the in-memory `storage/memory` implementation are not affected. User interaction is required for an application using filesystem-backed storage to interact with a malicious Git server or otherwise process attacker-controlled reference names.
Affected software
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
Public Cloud Module
amazon-ssm-agent
How to mitigate CVE-2026-71557
amazon-ssm-agent - update to 3.3.5226.0-150000.5.40.1