{"thread":{"id":"65080","subject":"Git for Win - CVE-2025-68121 - Impact Analysis and Fix","startedAt":"2026-02-26T18:09:41Z","lastAt":"2026-02-26T18:09:41Z","messageCount":1,"participants":["Matthiesen, Jan"],"isPatch":false,"patchVersion":null,"patchTotal":null},"messages":[{"id":"537214","messageId":"d65bd23d95fb4ae19651e83f4578850a@bwi.de","threadId":"65080","inReplyTo":null,"subject":"Git for Win - CVE-2025-68121 - Impact Analysis and Fix","fromName":"Matthiesen, Jan","fromEmail":"jan.matthiesen@bwi.de","sentAt":"2026-02-26T18:08:29Z","receivedAt":"2026-02-26T18:09:41Z","isPatch":false,"sender":{"key":"jan.matthiesen@bwi.de","avatar":null},"body":"Hi Git dev team,\n\nwe've noted above critical CVE (CVSS 10.0) and wanted to inquire about any possible dependencies for the (2.53.0) x64 version of Git for Windows and any fix perspective. \nGiven Git is not a Google tool it should be quick to decide and respond to.\n\nThe CVE relates to packet crypto/tls in the standard library of Go (Golang).\nImpacted software: Go-versions prior to 1.26.0-rc.1 plus distros based on it (e.g. Debian Bullseye/Bookworm, RHEL 10, Ubuntu).\n\nHow can we ensure the latest Git version is not or no longer impacted by this CV?\n\nKind regards\nJan.Matthiesen@bwi.de\n"}]}