CVE-2026-71556
Vulnerability Summary
Timeline
Description
go-git is an extensible git implementation library written in pure Go. Prior to 5.19.2 and 6.0.0-alpha.5, worktree operations (including checkout, status, and add) resolve symbolic links inside the working tree without confining resolution to the worktree boundary, so a maliciously crafted repository containing a symlink can cause go-git to read from or write to files outside the intended working directory when the repository is cloned and its worktree operations are used. Versions 5.19.2 and 6.0.0-alpha.5.
CVSS Metrics
- v3.1•HIGH•Score: 7.1CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L
EPSS Trends
Current EPSS score: 0.36%• Percentile: 30%
Techniques & Countermeasures
- CWE-59•Improper Link Resolution Before File Access ('Link Following')
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
Affected Systems
- chainguard•act
< 0.2.89-r5
- chainguard•amazon-ssm-agent
< 3.3.4851.0-r2
- chainguard•amazon-ssm-agent-ecs-exec
< 3.3.4851.0-r2
- chainguard•amazon-ssm-agent-ecs-exec-fips
< 3.3.4851.0-r2
- chainguard•amazon-ssm-agent-fips
< 3.3.4851.0-r2
- chainguard•argo-cd-3.1
all
- chainguard•argo-cd-3.1-compat
all
- chainguard•argo-cd-3.2
all
- chainguard•argo-cd-3.2-compat
all
- chainguard•argo-cd-3.3
< 3.3.14-r1
- chainguard•argo-cd-3.3-compat
< 3.3.14-r1 | < 3.3.14-r9 | < 0
- chainguard•argo-cd-3.4
< 3.4.7-r1
- chainguard•argo-cd-3.4-compat
< 3.4.7-r1
- chainguard•argo-cd-3.5
< 3.5.1-r1
- chainguard•argo-cd-3.5-compat
< 3.5.1-r1
- chainguard•argo-cd-fips-3.1
all
- chainguard•argo-cd-fips-3.1-compat
all
- chainguard•argo-cd-fips-3.2
all
- chainguard•argo-cd-fips-3.2-compat
all
- chainguard•argo-cd-fips-3.3
< 3.3.14-r1
- chainguard•argo-cd-fips-3.3-compat
< 3.3.14-r1
- chainguard•argo-cd-fips-3.4
< 3.4.7-r1
- chainguard•argo-cd-fips-3.4-compat
< 3.4.7-r1
- chainguard•argo-cd-fips-3.5
< 3.5.1-r1
- chainguard•argo-cd-fips-3.5-compat
< 3.5.1-r1
- chainguard•argo-events
< 1.9.11-r2
- chainguard•argo-events-fips
< 1.9.11-r4
- chainguard•argo-workflow-executor-3.7
< 3.7.17-r2
- chainguard•argo-workflow-executor-4.0
< 4.0.8-r3
- chainguard•argo-workflow-executor-fips-3.7
< 3.7.17-r1
- chainguard•argo-workflow-executor-fips-4.0
< 4.0.8-r3
- chainguard•argo-workflows-3.7
< 3.7.17-r2
- chainguard•argo-workflows-4.0
< 4.0.8-r3
- chainguard•argo-workflows-fips-3.7
< 3.7.17-r1
- chainguard•argo-workflows-fips-4.0
< 4.0.8-r3
- chainguard•argo-workflows-ui-4.0
< 4.0.11-r0
- chainguard•argocd-image-updater
< 1.2.2-r7
- chainguard•argocd-image-updater-fips
< 1.2.2-r9
- chainguard•bom
< 0.7.1-r24
- chainguard•boring-registry
< 0.19.0-r1
- chainguard•boring-registry-fips
< 0.19.0-r1
- chainguard•cerbos
< 0.54.0-r2 | all
- chainguard•cerbos-fips
< 0.54.0-r2
- chainguard•cerbosctl
< 0.54.0-r2
- chainguard•cerbosctl-fips
< 0.54.0-r2
- chainguard•chainloop-cli
< 1.105.8-r1
- chainguard•chainloop-cli-fips
< 1.105.8-r0
- chainguard•cloudbeat-8.17
< 8.17.10-r34
- chainguard•cloudbeat-8.19
< 8.19.19-r2
- chainguard•cloudbeat-9.2
< 9.2.8-r17
Showing first 50 affected entries in server-rendered view.
References (23)
- https://github.com/go-git/go-git/security/advisories/GHSA-hc8v-wwc9-vgxm
- https://github.com/go-git/go-git/commit/008a78f2dd86f52544ddff8b8e8ddeecdf3f7aab
- https://github.com/go-git/go-git/commit/661d1c7f101d34e002a3cfcf8dbea5b7421d07ac
- https://github.com/go-git/go-git/releases/tag/v5.19.2
- https://github.com/go-git/go-git/releases/tag/v6.0.0-alpha.5
- https://ubuntu.com/security/CVE-2026-71556
- https://www.cve.org/CVERecord?id=CVE-2026-71556
- https://security-tracker.debian.org/tracker/CVE-2026-71556
- https://github.com/go-git/go-git
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/71xxx/CVE-2026-71556.json
- https://nvd.nist.gov/vuln/detail/CVE-2026-71556
- https://access.redhat.com/errata/RHSA-2026:60646
- https://images.redhat.com/
- https://access.redhat.com/security/cve/CVE-2026-71556
- https://access.redhat.com/security/updates/classification/
- https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_60646.json
- https://bugzilla.redhat.com/show_bug.cgi?id=2512562
- https://access.redhat.com/errata/RHSA-2026:60793
- https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_60793.json
- https://access.redhat.com/errata/RHSA-2026:66208
- https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_66208.json
- https://access.redhat.com/errata/RHSA-2026:66421
- https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_66421.json