CVE-2026-25934
Vulnerability Summary
Timeline
Description
go-git is a highly extensible git implementation library written in pure Go. Prior to 5.16.5, a vulnerability was discovered in go-git whereby data integrity values for .pack and .idx files were not properly verified. This resulted in go-git potentially consuming corrupted files, which would likely result in unexpected errors such as object not found. For context, clients fetch packfiles from upstream Git servers. Those files contain a checksum of their contents, so that clients can perform integrity checks before consuming it. The pack indexes (.idx) are generated locally by go-git, or the git cli, when new .pack files are received and processed. The integrity checks for both files were not being verified correctly. This vulnerability is fixed in 5.16.5.
CVSS Metrics
- v3.1•MEDIUM•Score: 4.3CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
EPSS Trends
Current EPSS score: 0.14%• Percentile: 4%
Techniques & Countermeasures
- CWE-354•Improper Validation of Integrity Check Value
The product does not validate or incorrectly validates the integrity check values or "checksums" of a message. This may prevent it from detecting if the data has been modified or corrupted in transmission.
Affected Systems
- chainguard•amazon-ssm-agent
< 3.3.3270.0-r5
- chainguard•amazon-ssm-agent-ecs-exec
< 3.3.3270.0-r5
- chainguard•amazon-ssm-agent-ecs-exec-fips
< 3.3.3270.0-r6
- chainguard•amazon-ssm-agent-fips
< 3.3.3270.0-r6
- chainguard•apko
< 1.1.6-r1
- chainguard•apko-fips
< 1.1.6-r1
- chainguard•argo-cd-2.13
< 2.13.9-r8
- chainguard•argo-cd-2.13-compat
< 2.13.9-r8
- chainguard•argo-cd-2.14
< 2.14.21-r8
- chainguard•argo-cd-2.14-compat
< 2.14.21-r8
- chainguard•argo-cd-3.0
< 3.0.23-r2
- chainguard•argo-cd-3.0-compat
< 3.0.23-r2
- chainguard•argo-cd-3.1
< 3.1.12-r3
- chainguard•argo-cd-3.1-compat
< 3.1.12-r3
- chainguard•argo-cd-3.2
< 3.2.6-r3
- chainguard•argo-cd-3.2-compat
< 3.2.6-r3
- chainguard•argo-cd-fips-2.14
all
- chainguard•argo-cd-fips-2.14-compat
all
- chainguard•argo-cd-fips-3.0
< 3.0.23-r2
- chainguard•argo-cd-fips-3.0-compat
< 3.0.23-r2
- chainguard•argo-cd-fips-3.1
< 3.1.12-r2
- chainguard•argo-cd-fips-3.1-compat
< 3.1.12-r2
- chainguard•argo-cd-fips-3.2
< 3.2.6-r3
- chainguard•argo-cd-fips-3.2-compat
< 3.2.6-r3
- chainguard•argo-events
< 1.9.10-r3
- chainguard•argo-events-fips
< 1.9.10-r2
- chainguard•argo-workflow-executor-3.6
< 3.6.19-r1
- chainguard•argo-workflow-executor-3.7
< 3.7.10-r0
- chainguard•argo-workflow-executor-fips-3.6
< 3.6.18-r3
- chainguard•argo-workflow-executor-fips-3.7
< 3.7.10-r0
- chainguard•argo-workflows-3.6
< 3.6.19-r1
- chainguard•argo-workflows-3.7
< 3.7.10-r0
- chainguard•argo-workflows-fips-3.6
< 3.6.18-r3
- chainguard•argo-workflows-fips-3.7
< 3.7.10-r0
- chainguard•argocd-image-updater
< 1.1.0-r1
- chainguard•argocd-image-updater-fips
< 1.1.0-r2
- chainguard•bom
< 0.7.1-r6
- chainguard•cerbos
< 0.51.0-r2
- chainguard•cerbos-fips
< 0.51.0-r1
- chainguard•cerbosctl
< 0.51.0-r2
- chainguard•cerbosctl-fips
< 0.51.0-r1
- chainguard•cg
< 0.2.203-r0
- chainguard•chainctl
< 0.2.206-r0
- chainguard•chezmoi
< 2.69.3-r2
- chainguard•cloudbeat-8.17
< 8.17.10-r7
- chainguard•cloudbeat-8.18
< 8.18.8-r8
- chainguard•cloudbeat-8.19
< 8.19.11-r1
- chainguard•cloudbeat-9.0
< 9.0.8-r7
- chainguard•cloudbeat-9.1
< 9.1.10-r2
- chainguard•cloudbeat-9.2
< 9.2.5-r2
Showing first 50 affected entries in server-rendered view.
References (6)
- https://github.com/go-git/go-git/security/advisories/GHSA-37cx-329c-33x3
- https://github.com/go-git/go-git/releases/tag/v5.16.5
- https://github.com/go-git/go-git
- https://nvd.nist.gov/vuln/detail/CVE-2026-25934
- https://security-tracker.debian.org/tracker/CVE-2026-25934
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/25xxx/CVE-2026-25934.json