Skip to content

Conversation

@go-git-renovate
Copy link
Contributor

@go-git-renovate go-git-renovate bot commented Nov 23, 2025

This PR contains the following updates:

Package Change Age Confidence
github.com/go-git/go-git/v5 v5.12.0 -> v5.13.0 age confidence

go-git has an Argument Injection via the URL field

CVE-2025-21613 / GHSA-v725-9546-7q7m / GO-2025-3368

More information

Details

Impact

An argument injection vulnerability was discovered in go-git versions prior to v5.13.

Successful exploitation of this vulnerability could allow an attacker to set arbitrary values to git-upload-pack flags. This only happens when the file transport protocol is being used, as that is the only protocol that shells out to git binaries.

Affected versions

Users running versions of go-git from v4 and above are recommended to upgrade to v5.13 in order to mitigate this vulnerability.

Workarounds

In cases where a bump to the latest version of go-git is not possible, we recommend users to enforce restrict validation rules for values passed in the URL field.

Credit

Thanks to @​vin01 for responsibly disclosing this vulnerability to us.

Severity

  • CVSS Score: 9.2 / 10 (Critical)
  • Vector String: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Clear

References

This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).


go-git clients vulnerable to DoS via maliciously crafted Git server replies

CVE-2025-21614 / GHSA-r9px-m959-cxf4 / GO-2025-3367

More information

Details

Impact

A denial of service (DoS) vulnerability was discovered in go-git versions prior to v5.13. This vulnerability allows an attacker to perform denial of service attacks by providing specially crafted responses from a Git server which triggers resource exhaustion in go-git clients.

This is a go-git implementation issue and does not affect the upstream git cli.

Patches

Users running versions of go-git from v4 and above are recommended to upgrade to v5.13 in order to mitigate this vulnerability.

Workarounds

In cases where a bump to the latest version of go-git is not possible, we recommend limiting its use to only trust-worthy Git servers.

Credit

Thanks to Ionut Lalu for responsibly disclosing this vulnerability to us.

Severity

  • CVSS Score: 7.5 / 10 (High)
  • Vector String: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

References

This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).


Argument Injection via the URL field in github.com/go-git/go-git

CVE-2025-21613 / GHSA-v725-9546-7q7m / GO-2025-3368

More information

Details

Argument Injection via the URL field in github.com/go-git/go-git

Severity

Unknown

References

This data is provided by OSV and the Go Vulnerability Database (CC-BY 4.0).


Clients vulnerable to DoS via maliciously crafted Git server replies in github.com/go-git/go-git

CVE-2025-21614 / GHSA-r9px-m959-cxf4 / GO-2025-3367

More information

Details

Clients vulnerable to DoS via maliciously crafted Git server replies in github.com/go-git/go-git

Severity

Unknown

References

This data is provided by OSV and the Go Vulnerability Database (CC-BY 4.0).


Release Notes

go-git/go-git (github.com/go-git/go-git/v5)

v5.13.0

Compare Source

What's Changed

New Contributors

Full Changelog: v5.12.0...v5.13.0


Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Renovate Bot.

@go-git-renovate go-git-renovate bot added the dependencies Pull requests that update a dependency file label Nov 23, 2025
@go-git-renovate
Copy link
Contributor Author

go-git-renovate bot commented Nov 23, 2025

ℹ Artifact update notice

File name: cli/go-git/go.mod

In order to perform the update(s) described in the table above, Renovate ran the go get command, which resulted in the following additional change(s):

  • 6 additional dependencies were updated

Details:

Package Change
github.com/ProtonMail/go-crypto v1.0.0 -> v1.1.3
github.com/cyphar/filepath-securejoin v0.2.4 -> v0.2.5
github.com/go-git/go-billy/v5 v5.5.0 -> v5.6.0
github.com/skeema/knownhosts v1.2.2 -> v1.3.0
golang.org/x/mod v0.12.0 -> v0.17.0
golang.org/x/tools v0.13.0 -> v0.21.1-0.20240508182429-e35e4ccd0d2d

@go-git-renovate go-git-renovate bot changed the title fix(deps): update module github.com/go-git/go-git/v5 to v5.13.0 [security] (releases/v5.x) build: Update module github.com/go-git/go-git/v5 to v5.13.0 [SECURITY] (releases/v5.x) Nov 23, 2025
@go-git-renovate go-git-renovate bot force-pushed the renovate/releases/v5.x-go-github.com-go-git-go-git-v5-vulnerability branch 2 times, most recently from b7b627b to a8e82da Compare November 23, 2025 21:58
@pjbgf pjbgf force-pushed the renovate/releases/v5.x-go-github.com-go-git-go-git-v5-vulnerability branch from 06541f2 to 3e752f0 Compare November 23, 2025 22:26
@pjbgf pjbgf merged commit de8ecc3 into releases/v5.x Nov 23, 2025
31 of 32 checks passed
@pjbgf pjbgf deleted the renovate/releases/v5.x-go-github.com-go-git-go-git-v5-vulnerability branch November 23, 2025 22:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants