Heap-based buffer overflow in Git for Windows - #VU152717
Published: September 29, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service and prevent a rejected credential from being removed.
The vulnerability exists due to a heap-based buffer overflow in the match_cred_password() function of git-credential-wincred when comparing a supplied password with a saved Windows Credential Manager CredentialBlob during credential erasure. A remote attacker can cause a victim to initiate credential rejection for a target with a saved credential to cause a denial of service and prevent a rejected credential from being removed.
The overwrite consists of a fixed two-byte NUL value.