Where
-Infinity
0

Vendor Risk Score

See how git-scm compares to other vendors in security performance

View Risk Score →

git-scm GitGit Link Following Vulnerability

Risk 89
Severity
8.1
First published (updated )

redhat/gitGit vulnerable to Remote Code Execution while cloning special-crafted local repositories

Risk 74
Severity
8.2
First published (updated )

redhat/gitCloning local Git repository by untrusted user allows the untrusted user to modify objects in the cloned repository at will

Risk 27
Severity
3.9
First published (updated )

redhat/gitLocal Git clone may hardlink arbitrary user-readable files into the new repository's "objects/" directory

Risk 55
Severity
7.1
First published (updated )

redhat/gitGit's protections for cloning untrusted repositories can be bypassed

Risk 73
Severity
7.8
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

git-scm GitArbitrary configuration injection via `git submodule deinit`

Risk 72
Severity
7.8
First published (updated )

git-scm Git"git apply --reject" partially-controlled arbitrary file write

Risk 46
Severity
7.5
First published (updated )

git-scm GitGit vulnerable to local clone-based data exfiltration with non-local transports

Risk 33
Severity
5.5
First published (updated )

git-scm GitGit's `git apply` overwriting paths outside the working tree

Risk 45
Severity
7.5
First published (updated )

git-scm GitGit clone remote code execution vulnerability in git-for-windows

Risk 70
Severity
8.6
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

git-scm Gitgitattributes parsing integer overflow in git

Risk 89
Severity
9.8
First published (updated )

git-scm GitInteger overflow in `git archive`, `git log --format` leading to RCE in git

Risk 89
Severity
9.8
First published (updated )

redhat/gitGit subject to exposure of sensitive information via local clone of symbolic links

Risk 34
Severity
5.5
First published (updated )

redhat/gitGit vulnerable to Remote Code Execution via Heap overflow in `git shell`

Risk 81
Severity
8.8
First published (updated )

redhat/gitBypass of safe.directory protections in Git

Risk 73
Severity
7.8
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

redhat/gitUncontrolled search for the Git directory in Git for Windows

Risk 72
Severity
7.8
First published (updated )

git-scm GitThe --mirror documentation for Git through 2.35.1 does not mention the availability of deleted conte…

Risk 43
Severity
7.5
First published (updated )

git-scm Gitgit_connect_git in connect.c in Git before 2.30.1 allows a repository path to contain a newline char…

Risk 43
Severity
7.5
First published (updated )

git-scm Gitmalicious repositories can execute remote code while cloning

Risk 59
Severity
8
First published (updated )

git-scm GitMalicious URLs can still cause Git to send a stored credential to the wrong server

Risk 45
Severity
7.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

git-scm Gitmalicious URLs may cause Git to present stored credentials to the wrong server

Risk 69
Severity
9.3
First published (updated )

git-scm GitInput Validation

Risk 89
Severity
9.8
First published (updated )

git-scm GitAn issue was found in Git before v2.24.1, v2.23.1, v2.22.2, v2.21.1, v2.20.2, v2.19.3, v2.18.2, v2.1…

Risk 86
Severity
9.8
First published (updated )

git-scm GitDependency Update

Risk 79
Severity
9.3
First published (updated )

git-scm GitRecursive clones are currently affected by a vulnerability that is caused by too-lax validation of s…

Risk 77
Severity
8.8
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

git-scm GitInput Validation

Risk 25
Severity
3.6
First published (updated )

git-scm GitLast updated 25 August 2025

Risk 90
Severity
9.8
First published (updated )

redhat Enterprise LinuxLast updated 25 August 2025

Risk 90
Severity
9.8
First published (updated )

redhat/gitLast updated 25 August 2025

Risk 45
Severity
7.5
First published (updated )

redhat/gitPath Traversal

Risk 71
Severity
7.8
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203