What is CVE-2026-71557?
CVE-2026-71557 affects go-git: reference names are not sanitized before constructing on-disk paths under the reference storage directory, leading to potential directory traversal via crafted reference names. This impacts versions prior to 5.19.2; update to the patched version is required.
Azərbaycanca: CVE-2026-71557 go-git kitabxanasında aşkarlanıb: istinad adları diska yazılan yollar qurulmazdan əvvəl təmizlənmir. Bu, xüsusi hazırlanmış zərərli referans adı vasitəsilə kataloq keçidinə səbəb ola bilər. Təsirə məruz qalan versiyalar: 5.19.2-dən əvvəlki versiyalar. Yeniləmə tətbiq edilməlidir.
Related CVEs
link basis: same weakness class CWE-22
FAQ2
What security issue can CVE-2026-71557 cause in the go-git library?
It can lead to directory traversal via crafted reference names, because reference names are not sanitized before constructing on-disk paths under the reference storage directory.
Which version should be updated to in order to mitigate CVE-2026-71557?
An update to version 5.19.2 or later should be applied, as versions prior to 5.19.2 are affected.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.