Improper Validation of Array Index Affecting witness package, versions <0.10.2-r16


Severity

Recommended
low

Based on default assessment until relevant scores are available.

Threat Intelligence

EPSS
0.01% (3rd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-WOLFILATEST-WITNESS-15889459
  • published4 Apr 2026
  • disclosed31 Mar 2026

Introduced: 31 Mar 2026

NewCVE-2026-33762  (opens in a new tab)
CWE-129  (opens in a new tab)

How to fix?

Upgrade Wolfi witness to version 0.10.2-r16 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream witness package and not the witness package as distributed by Wolfi. See How to fix? for Wolfi relevant fixed versions and status.

go-git is an extensible git implementation library written in pure Go. Prior to version 5.17.1, go-git’s index decoder for format version 4 fails to validate the path name prefix length before applying it to the previously decoded path name. A maliciously crafted index file can trigger an out-of-bounds slice operation, resulting in a runtime panic during normal index parsing. This issue only affects Git index format version 4. Earlier formats (go-git supports only v2 and v3) are not vulnerable to this issue. This issue has been patched in version 5.17.1.

CVSS Base Scores

version 3.1