Incorrect Behavior Order: Validate Before Canonicalize Affecting github.com/go-git/go-git/plumbing/object package, versions <5.19.0>=6.0.0-alpha.1 <6.0.0-alpha.3


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.16% (6th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-GOLANG-GITHUBCOMGOGITGOGITPLUMBINGOBJECT-16638687
  • published11 May 2026
  • disclosed11 May 2026
  • creditStian Kristoffersen

Introduced: 11 May 2026

CVE-2026-45022  (opens in a new tab)
CWE-180  (opens in a new tab)

How to fix?

Upgrade github.com/go-git/go-git/plumbing/object to version 5.19.0, 6.0.0-alpha.3 or higher.

Overview

Affected versions of this package are vulnerable to Incorrect Behavior Order: Validate Before Canonicalize in the parsing of Git objects with malformed or ambiguous commit or tag objects. An attacker can cause inconsistent interpretation of object metadata or signature validation by introducing specially crafted objects that are parsed differently than by upstream Git, potentially leading to the acceptance of commits with misleading or unintended metadata.

CVSS Base Scores

version 4.0
version 3.1