Git is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-level operations and full access to internals. When cloning a repository Git knows to optionally fetch a bundle advertised by the remote server, which allows the server-side to offload parts of the clone to a CDN. The Git client does not perform sufficient validation of the advertised bundles, which allows the remote side to perform protocol injection. This protocol injection can cause the client to write the fetched bundle to a location controlled by the adversary. The fetched content is fully controlled by the server, which can in the worst case lead to arbitrary code execution. The use of bundle URIs is not enabled by default and can be controlled by the bundle.heuristic config option. Some cases of the vulnerability require that the adversary is in control of where a repository will be cloned to. This either requires social engineering or a recursive clone with submodules. These cases can thus be avoided by disabling recursive clones. This vulnerability is fixed in v2.43.7, v2.44.4, v2.45.4, v2.46.4, v2.47.3, v2.48.2, v2.49.1, and v2.50.1.
CVSS Details
- CVSS 4.0 Base Score: 8.6 (HIGH)
- CVSS 4.0 Vector: (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade gitwebUpgrade gitkUpgrade git-allUpgrade git-instawebUpgrade git-credential-libsecretUpgrade git-emailUpgrade git-core-docUpgrade perl-GitUpgrade git-guiUpgrade git-coreUpgrade git-daemonUpgrade gitUpgrade git-svnUpgrade git-subtreeUpgrade perl-Git-SVN | Jul 24, 2025 | Jul 8, 2025 |
| Alpine Linux | — | Upgrade git | Aug 8, 2025 | Jul 8, 2025 |
| Amazon Linux Ami 2 | — | Upgrade git-instawebUpgrade perl-GitUpgrade gitwebUpgrade git-guiUpgrade git-core-docUpgrade git-allUpgrade git-daemonUpgrade gitkUpgrade git-p4Upgrade git-debuginfoUpgrade perl-Git-SVNUpgrade git-subtreeUpgrade git-credential-libsecretUpgrade git-coreUpgrade git-emailUpgrade git-cvsUpgrade gitUpgrade git-svn | May 20, 2026 | May 20, 2026 |
| Amazon_linux_2023 | — | Upgrade git-p4Upgrade git-credential-libsecret-debuginfoUpgrade git-core-debuginfoUpgrade git-emailUpgrade git-subtreeUpgrade gitkUpgrade git-cvsUpgrade git-allUpgrade git-debuginfoUpgrade git-guiUpgrade git-daemonUpgrade git-instawebUpgrade git-core-docUpgrade git-svnUpgrade git-daemon-debuginfoUpgrade perl-Git-SVNUpgrade git-debugsourceUpgrade git-coreUpgrade perl-GitUpgrade gitwebUpgrade git-credential-libsecretUpgrade git | Jul 30, 2025 | Jul 8, 2025 |
| Debian | — | No solution existsUpgrade git | Jul 10, 2025 | Jul 8, 2025 |
| Freebsd | — | Upgrade git-guiUpgrade git-svnUpgrade git-p4Upgrade gitUpgrade git-cvs | Jul 9, 2025 | Jul 8, 2025 |
| Gentoo Linux | — | Upgrade dev-vcs/git. | Jul 9, 2025 | Jul 8, 2025 |
| Microsoft Visual_studio | — | Update Microsoft Visual Studio 2022 to the latest version in the LTSC 17.10 version stream, or upgrade to a newer supported version of Visual Studio 2022.Update Microsoft Visual Studio 2022 to the latest version in the current channel channel.Update Microsoft Visual Studio 2022 to the latest version in the LTSC 17.12 version stream, or upgrade to a newer supported version of Visual Studio 2022.Update Microsoft Visual Studio 2019 to the latest version in the LTSC 16.11 version stream, or upgrade to a newer supported version of Visual Studio 2019.Update Microsoft Visual Studio 2022 to the latest version in the LTSC 17.8 version stream, or upgrade to a newer supported version of Visual Studio 2022. | Jul 10, 2025 | Jul 8, 2025 |
| Oracle_linux | — | Upgrade gitUpgrade gitkUpgrade gitwebUpgrade git-core-docUpgrade git-credential-libsecretUpgrade git-subtreeUpgrade git-allUpgrade git-instawebUpgrade git-guiUpgrade git-emailUpgrade git-daemonUpgrade perl-Git-SVNUpgrade perl-GitUpgrade git-svnUpgrade git-core | Jul 23, 2025 | Jul 8, 2025 |
| Redhat Openshift | — | Upgrade rhcos | Aug 10, 2026 | Jul 8, 2025 |
| Redhat_linux | — | Upgrade git-svnUpgrade git-allUpgrade git-credential-libsecretUpgrade gitUpgrade perl-GitUpgrade git-subtreeUpgrade git-credential-libsecret-debuginfoUpgrade git-emailUpgrade git-debuginfoUpgrade git-core-docUpgrade perl-Git-SVNUpgrade git-daemon-debuginfoNo solution existsUpgrade git-coreUpgrade gitkUpgrade gitwebUpgrade git-core-debuginfoUpgrade git-daemonUpgrade git-instawebUpgrade git-guiUpgrade git-debugsource | Jul 9, 2025 | Jul 8, 2025 |
| Rocky_linux | — | Upgrade git-debugsourceUpgrade git-core-debuginfoUpgrade git-coreUpgrade git-daemon-debuginfoUpgrade git-daemonUpgrade git-credential-libsecretUpgrade git-debuginfoUpgrade gitUpgrade git-credential-libsecret-debuginfoUpgrade git-subtree | Feb 5, 2026 | Jul 29, 2025 |
| Suse | — | Upgrade git-p4Upgrade git-webUpgrade git-archUpgrade gitkUpgrade git-lfsUpgrade gitUpgrade perl-gitUpgrade git-daemonUpgrade git-docUpgrade git-coreUpgrade git-credential-libsecretUpgrade git-cvsUpgrade git-guiUpgrade git-svnUpgrade git-email | Dec 5, 2025 | Jul 22, 2025 |
| Ubuntu | — | Upgrade git-gui (Ubuntu Pro)Upgrade gitUpgrade gitkUpgrade git (Ubuntu Pro)Upgrade git-guiUpgrade gitk (Ubuntu Pro) | Jul 9, 2025 | Jul 8, 2025 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jul 10, 2025 | Jul 8, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub