WhisperX tag archive

#Go-Git

This page collects WhisperX intelligence signals tagged #Go-Git. It is designed for humans, search engines, and AI agents: each item links to a canonical source-backed record with sector, source, timestamp, credibility, and exportable structured data.

Latest Signals (2)

The Lab · 2026-03-31 01:27:05 · GitHub Issues

1. Go-Git v5.17.1 Patches Critical Index Decoder Vulnerability (CVE-2026-33762)

A critical security flaw in the widely used `go-git` library has been patched in version 5.17.1. The vulnerability, tracked as CVE-2026-33762, resides in the index decoder for format version 4. The decoder fails to perform a crucial validation step, allowing a maliciously crafted Git index file to trigger an out-of-bou...

The Lab · 2026-04-20 02:22:32 · GitHub Issues

2. Go-Git Library Exposes Critical Integrity Flaw: CVE-2026-25934 Targets .idx and .pack Files

A newly disclosed security vulnerability in the widely used Go-Git library exposes a critical flaw in how it verifies data integrity. The vulnerability, tracked as CVE-2026-25934 (GHSA-37cx-329c-33x3), stems from improper verification of data integrity values for .idx and .pack files. This core failure in a fundamental...