Out-of-bounds write in Git for Windows - CVE-2026-100407
Published: September 29, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service or prevent OAuth credentials from being persisted.
The vulnerability exists due to an out-of-bounds write in the git-credential-wincred store OAuth credential formatting path when storing credentials containing a password and oauth_refresh_token. A remote attacker can cause a victim to process crafted credential input to cause a denial of service or prevent OAuth credentials from being persisted.
User interaction is required.