Git is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-level operations and full access to internals. When cloning a repository Git knows to optionally fetch a bundle advertised by the remote server, which allows the server-side to offload parts of the clone to a CDN. The Git client does not perform sufficient validation of the advertised bundles, which allows the remote side to perform protocol injection. This protocol injection can cause the client to write the fetched bundle to a location controlled by the adversary. The fetched content is fully controlled by the server, which can in the worst case lead to arbitrary code execution. The use of bundle URIs is not enabled by default and can be controlled by the bundle.heuristic config option. Some cases of the vulnerability require that the adversary is in control of where a repository will be cloned to. This either requires social engineering or a recursive clone with submodules. These cases can thus be avoided by disabling recursive clones. This vulnerability is fixed in v2.43.7, v2.44.4, v2.45.4, v2.46.4, v2.47.3, v2.48.2, v2.49.1, and v2.50.1.
CVSS Details
- CVSS 4.0 Base Score: 8.6 (HIGH)
- CVSS 4.0 Vector: (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade git-emailUpgrade git-core-docUpgrade gitwebUpgrade git-credential-libsecretUpgrade perl-GitUpgrade gitkUpgrade git-allUpgrade git-guiUpgrade git-instawebUpgrade perl-Git-SVNUpgrade git-coreUpgrade gitUpgrade git-daemonUpgrade git-subtreeUpgrade git-svn | Jul 24, 2025 | Jul 8, 2025 |
| Alpine Linux | — | Upgrade git | Aug 8, 2025 | Jul 8, 2025 |
| Amazon Linux Ami 2 | — | Upgrade perl-GitUpgrade git-guiUpgrade git-allUpgrade git-core-docUpgrade git-instawebUpgrade git-daemonUpgrade gitwebUpgrade perl-Git-SVNUpgrade gitkUpgrade git-emailUpgrade git-p4Upgrade git-svnUpgrade git-cvsUpgrade git-debuginfoUpgrade git-subtreeUpgrade git-coreUpgrade gitUpgrade git-credential-libsecret | May 20, 2026 | May 20, 2026 |
| Amazon_linux_2023 | — | Upgrade git-instawebUpgrade git-emailUpgrade git-allUpgrade git-daemonUpgrade git-debuginfoUpgrade git-cvsUpgrade git-core-docUpgrade git-subtreeUpgrade git-core-debuginfoUpgrade git-p4Upgrade git-credential-libsecret-debuginfoUpgrade git-guiUpgrade gitkUpgrade git-svnUpgrade perl-GitUpgrade git-debugsourceUpgrade gitUpgrade gitwebUpgrade git-daemon-debuginfoUpgrade git-credential-libsecretUpgrade perl-Git-SVNUpgrade git-core | Jul 30, 2025 | Jul 8, 2025 |
| Debian | — | Upgrade gitNo solution exists | Jul 10, 2025 | Jul 8, 2025 |
| Freebsd | — | Upgrade git-guiUpgrade git-svnUpgrade git-p4Upgrade gitUpgrade git-cvs | Jul 9, 2025 | Jul 8, 2025 |
| Gentoo Linux | — | Upgrade dev-vcs/git. | Jul 9, 2025 | Jul 8, 2025 |
| Microsoft Visual_studio | — | Update Microsoft Visual Studio 2022 to the latest version in the LTSC 17.8 version stream, or upgrade to a newer supported version of Visual Studio 2022.Update Microsoft Visual Studio 2019 to the latest version in the LTSC 16.11 version stream, or upgrade to a newer supported version of Visual Studio 2019.Update Microsoft Visual Studio 2022 to the latest version in the LTSC 17.10 version stream, or upgrade to a newer supported version of Visual Studio 2022.Update Microsoft Visual Studio 2022 to the latest version in the LTSC 17.12 version stream, or upgrade to a newer supported version of Visual Studio 2022.Update Microsoft Visual Studio 2022 to the latest version in the current channel channel. | Jul 10, 2025 | Jul 8, 2025 |
| Oracle_linux | — | Upgrade git-daemonUpgrade perl-GitUpgrade git-svnUpgrade git-coreUpgrade git-emailUpgrade perl-Git-SVNUpgrade git-instawebUpgrade git-guiUpgrade git-core-docUpgrade gitwebUpgrade gitkUpgrade gitUpgrade git-allUpgrade git-subtreeUpgrade git-credential-libsecret | Jul 23, 2025 | Jul 8, 2025 |
| Redhat Openshift | — | Upgrade rhcos | Aug 10, 2026 | Jul 8, 2025 |
| Redhat_linux | — | Upgrade git-guiUpgrade gitwebUpgrade git-daemon-debuginfoUpgrade git-coreUpgrade git-core-debuginfoUpgrade gitkUpgrade git-daemonUpgrade git-instawebUpgrade perl-Git-SVNNo solution existsUpgrade git-debugsourceUpgrade git-subtreeUpgrade git-credential-libsecret-debuginfoUpgrade git-emailUpgrade perl-GitUpgrade gitUpgrade git-core-docUpgrade git-debuginfoUpgrade git-credential-libsecretUpgrade git-allUpgrade git-svn | Jul 9, 2025 | Jul 8, 2025 |
| Rocky_linux | — | Upgrade git-debugsourceUpgrade git-daemonUpgrade git-daemon-debuginfoUpgrade git-coreUpgrade git-core-debuginfoUpgrade git-credential-libsecret-debuginfoUpgrade git-credential-libsecretUpgrade git-debuginfoUpgrade git-subtreeUpgrade git | Feb 5, 2026 | Jul 29, 2025 |
| Suse | — | Upgrade gitUpgrade git-webUpgrade gitkUpgrade git-p4Upgrade git-lfsUpgrade git-archUpgrade git-coreUpgrade git-svnUpgrade git-guiUpgrade git-docUpgrade git-daemonUpgrade git-emailUpgrade git-cvsUpgrade git-credential-libsecretUpgrade perl-git | Dec 5, 2025 | Jul 22, 2025 |
| Ubuntu | — | Upgrade gitk (Ubuntu Pro)Upgrade git (Ubuntu Pro)Upgrade git-guiUpgrade git-gui (Ubuntu Pro)Upgrade gitUpgrade gitk | Jul 9, 2025 | Jul 8, 2025 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jul 10, 2025 | Jul 8, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub