CVE-2026-41506
Vulnerability Summary
Timeline
Description
go-git is an extensible git implementation library written in pure Go. Prior to versions 5.18.0 and 6.0.0-alpha.2, go-git may leak HTTP authentication credentials when following redirects during smart-HTTP clone and fetch operations. This issue has been patched in versions 5.18.0 and 6.0.0-alpha.2.
CVSS Metrics
- v3.1•MEDIUM•Score: 4.7CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N
- v3.1•HIGH•Score: 7.4CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N
- v3.1•MEDIUM•Score: 6.5CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
EPSS Trends
Current EPSS score: 0.26%• Percentile: 18%
Techniques & Countermeasures
- CWE-522•Insufficiently Protected Credentials
The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
Affected Systems
- chainguard•act
< 0.2.87-r3
- chainguard•amazon-ssm-agent
< 3.3.3270.0-r13
- chainguard•amazon-ssm-agent-ecs-exec
< 3.3.3270.0-r13
- chainguard•amazon-ssm-agent-ecs-exec-fips
< 3.3.3270.0-r14
- chainguard•amazon-ssm-agent-fips
< 3.3.3270.0-r14
- chainguard•apko
< 1.2.3-r1
- chainguard•apko-fips
< 1.2.3-r1
- chainguard•argo-cd-2.14
all
- chainguard•argo-cd-2.14-compat
all
- chainguard•argo-cd-3.0
all
- chainguard•argo-cd-3.0-compat
all
- chainguard•argo-cd-3.1
< 3.1.15-r1
- chainguard•argo-cd-3.1-compat
< 3.1.15-r1
- chainguard•argo-cd-3.2
< 3.2.10-r1
- chainguard•argo-cd-3.2-compat
< 3.2.10-r1
- chainguard•argo-cd-3.3-compat
< 3.3.7-r2
- chainguard•argo-cd-fips-2.14
all
- chainguard•argo-cd-fips-2.14-compat
all
- chainguard•argo-cd-fips-3.0
all
- chainguard•argo-cd-fips-3.0-compat
all
- chainguard•argo-cd-fips-3.1
< 3.1.13-r6
- chainguard•argo-cd-fips-3.1-compat
< 3.1.13-r6
- chainguard•argo-cd-fips-3.2
< 3.2.8-r5
- chainguard•argo-cd-fips-3.2-compat
< 3.2.8-r5
- chainguard•argo-cd-fips-3.3
< 3.3.8-r2
- chainguard•argo-cd-fips-3.3-compat
< 3.3.8-r2
- chainguard•argo-events
< 1.9.10-r16
- chainguard•argo-events-fips
< 1.9.10-r11
- chainguard•argo-workflow-executor-3.6
< 3.6.19-r6
- chainguard•argo-workflow-executor-3.7
< 3.7.13-r2
- chainguard•argo-workflow-executor-4.0
< 4.0.4-r6
- chainguard•argo-workflow-executor-fips-3.6
< 3.6.19-r7
- chainguard•argo-workflow-executor-fips-3.7
< 3.7.13-r6
- chainguard•argo-workflow-executor-fips-4.0
< 4.0.4-r6
- chainguard•argo-workflows-3.6
< 3.6.19-r6
- chainguard•argo-workflows-3.7
< 3.7.13-r2
- chainguard•argo-workflows-4.0
< 4.0.4-r6
- chainguard•argo-workflows-fips-3.6
< 3.6.19-r7
- chainguard•argo-workflows-fips-3.7
< 3.7.13-r6
- chainguard•argo-workflows-fips-4.0
< 4.0.4-r6
- chainguard•argocd-image-updater
< 1.1.1-r9
- chainguard•argocd-image-updater-fips
< 1.1.1-r11
- chainguard•bom
< 0.7.1-r15
- chainguard•cerbos
< 0.51.0-r18
- chainguard•cerbos-fips
< 0.51.0-r12
- chainguard•cerbosctl
< 0.51.0-r18
- chainguard•cerbosctl-fips
< 0.51.0-r12
- chainguard•cg
< 0.2.245-r0
- chainguard•chainctl
< 0.2.248-r0
- chainguard•chainctl-fips
< 0.2.247-r0
Showing first 50 affected entries in server-rendered view.
References (14)
- https://github.com/go-git/go-git/security/advisories/GHSA-3xc5-wrhm-f963
- https://github.com/go-git/go-git/releases/tag/v5.18.0
- https://github.com/go-git/go-git/releases/tag/v6.0.0-alpha.2
- https://nvd.nist.gov/vuln/detail/CVE-2026-41506
- https://github.com/go-git/go-git
- https://access.redhat.com/errata/RHSA-2026:17669
- https://images.redhat.com/
- https://access.redhat.com/security/cve/CVE-2026-41506
- https://access.redhat.com/security/updates/classification/
- https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_17669.json
- https://bugzilla.redhat.com/show_bug.cgi?id=2468126
- https://www.cve.org/CVERecord?id=CVE-2026-41506
- https://security-tracker.debian.org/tracker/CVE-2026-41506
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/41xxx/CVE-2026-41506.json