Heap-based buffer overflow in Git for Windows - #VU152718
Published: September 29, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service and prevent OAuth credentials from being persisted.
The vulnerability exists due to a heap-based buffer overflow in the OAuth credential formatting logic of git-credential-wincred when storing an OAuth credential containing an oauth_refresh_token. A remote attacker can cause a victim to store an OAuth credential containing a refresh token to cause a denial of service and prevent OAuth credentials from being persisted.
The overwrite consists of a fixed two-byte NUL value.