ThreatCluster

Multiple CVEs Related to Malicious Git Server Replies Affect Go Applications

First seen 18 Feb 2026, 11:17 UTC Api.Msrc.Microsoft 41

Article Content

Browse articles
ThreatCluster

Two vulnerabilities have been identified in Git server responses affecting Go applications. CVE-2023-49568 can cause denial of service (DoS), while CVE-2023-49569 allows for path traversal and remote code execution (RCE). Both vulnerabilities were published on January 12, 2024.

Timeline

2024-01-12
CVE-2023-49568 and CVE-2023-49569 published
2026-02-18
Articles published detailing the vulnerabilities