Git is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-level operations and full access to internals. When cloning a repository Git knows to optionally fetch a bundle advertised by the remote server, which allows the server-side to offload parts of the clone to a CDN. The Git client does not perform sufficient validation of the advertised bundles, which allows the remote side to perform protocol injection. This protocol injection can cause the client to write the fetched bundle to a location controlled by the adversary. The fetched content is fully controlled by the server, which can in the worst case lead to arbitrary code execution. The use of bundle URIs is not enabled by default and can be controlled by the bundle.heuristic config option. Some cases of the vulnerability require that the adversary is in control of where a repository will be cloned to. This either requires social engineering or a recursive clone with submodules. These cases can thus be avoided by disabling recursive clones. This vulnerability is fixed in v2.43.7, v2.44.4, v2.45.4, v2.46.4, v2.47.3, v2.48.2, v2.49.1, and v2.50.1.
CVSS Details
- CVSS 4.0 Base Score: 8.6 (HIGH)
- CVSS 4.0 Vector: (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade git-allUpgrade git-emailUpgrade gitwebUpgrade git-credential-libsecretUpgrade git-guiUpgrade git-instawebUpgrade perl-GitUpgrade git-core-docUpgrade gitkUpgrade git-coreUpgrade git-svnUpgrade git-subtreeUpgrade perl-Git-SVNUpgrade git-daemonUpgrade git | Jul 24, 2025 | Jul 8, 2025 |
| Alpine Linux | — | Upgrade git | Aug 8, 2025 | Jul 8, 2025 |
| Amazon Linux Ami 2 | — | Upgrade git-core-docUpgrade git-instawebUpgrade git-allUpgrade perl-GitUpgrade git-daemonUpgrade git-guiUpgrade gitwebUpgrade git-svnUpgrade git-cvsUpgrade perl-Git-SVNUpgrade git-debuginfoUpgrade gitkUpgrade git-emailUpgrade git-p4Upgrade gitUpgrade git-subtreeUpgrade git-credential-libsecretUpgrade git-core | May 20, 2026 | May 20, 2026 |
| Amazon_linux_2023 | — | Upgrade git-coreUpgrade git-svnUpgrade perl-GitUpgrade git-credential-libsecretUpgrade perl-Git-SVNUpgrade gitwebUpgrade gitUpgrade git-debugsourceUpgrade git-daemon-debuginfoUpgrade git-daemonUpgrade gitkUpgrade git-cvsUpgrade git-core-docUpgrade git-debuginfoUpgrade git-p4Upgrade git-subtreeUpgrade git-emailUpgrade git-guiUpgrade git-core-debuginfoUpgrade git-credential-libsecret-debuginfoUpgrade git-instawebUpgrade git-all | Jul 30, 2025 | Jul 8, 2025 |
| Debian | — | No solution existsUpgrade git | Jul 10, 2025 | Jul 8, 2025 |
| Freebsd | — | Upgrade git-cvsUpgrade gitUpgrade git-p4Upgrade git-guiUpgrade git-svn | Jul 9, 2025 | Jul 8, 2025 |
| Gentoo Linux | — | Upgrade dev-vcs/git. | Jul 9, 2025 | Jul 8, 2025 |
| Microsoft Visual_studio | — | Update Microsoft Visual Studio 2022 to the latest version in the LTSC 17.8 version stream, or upgrade to a newer supported version of Visual Studio 2022.Update Microsoft Visual Studio 2019 to the latest version in the LTSC 16.11 version stream, or upgrade to a newer supported version of Visual Studio 2019.Update Microsoft Visual Studio 2022 to the latest version in the LTSC 17.12 version stream, or upgrade to a newer supported version of Visual Studio 2022.Update Microsoft Visual Studio 2022 to the latest version in the LTSC 17.10 version stream, or upgrade to a newer supported version of Visual Studio 2022.Update Microsoft Visual Studio 2022 to the latest version in the current channel channel. | Jul 10, 2025 | Jul 8, 2025 |
| Oracle_linux | — | Upgrade gitwebUpgrade gitUpgrade git-credential-libsecretUpgrade git-allUpgrade git-subtreeUpgrade gitkUpgrade git-core-docUpgrade git-daemonUpgrade git-emailUpgrade git-instawebUpgrade git-guiUpgrade perl-Git-SVNUpgrade perl-GitUpgrade git-svnUpgrade git-core | Jul 23, 2025 | Jul 8, 2025 |
| Redhat Openshift | — | Upgrade rhcos | Aug 10, 2026 | Jul 8, 2025 |
| Redhat_linux | — | Upgrade git-core-docUpgrade git-svnUpgrade git-credential-libsecret-debuginfoUpgrade git-credential-libsecretUpgrade gitUpgrade git-debuginfoUpgrade git-allUpgrade perl-GitUpgrade git-emailUpgrade git-subtreeUpgrade git-daemon-debuginfoUpgrade git-coreUpgrade git-instawebUpgrade git-guiUpgrade gitkUpgrade git-core-debuginfoUpgrade git-daemonUpgrade gitwebUpgrade perl-Git-SVNNo solution existsUpgrade git-debugsource | Jul 9, 2025 | Jul 8, 2025 |
| Rocky_linux | — | Upgrade git-coreUpgrade git-daemon-debuginfoUpgrade git-core-debuginfoUpgrade git-debugsourceUpgrade git-daemonUpgrade git-debuginfoUpgrade git-credential-libsecret-debuginfoUpgrade git-credential-libsecretUpgrade git-subtreeUpgrade git | Feb 5, 2026 | Jul 29, 2025 |
| Suse | — | Upgrade git-cvsUpgrade git-emailUpgrade git-svnUpgrade git-guiUpgrade git-daemonUpgrade git-docUpgrade perl-gitUpgrade git-credential-libsecretUpgrade git-coreUpgrade git-p4Upgrade git-archUpgrade gitUpgrade git-webUpgrade gitkUpgrade git-lfs | Dec 5, 2025 | Jul 22, 2025 |
| Ubuntu | — | Upgrade git (Ubuntu Pro)Upgrade gitk (Ubuntu Pro)Upgrade git-guiUpgrade git-gui (Ubuntu Pro)Upgrade gitUpgrade gitk | Jul 9, 2025 | Jul 8, 2025 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jul 10, 2025 | Jul 8, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub