git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Git for Win - CVE-2025-68121 - Impact Analysis and Fix

From
MJMatthiesen, Jan <jan.matthiesen@bwi.de>
Date
Feb 26, 2026, 18:08 UTC
Message-ID
<d65bd23d95fb4ae19651e83f4578850a@bwi.de>
Hi Git dev team,

we've noted above critical CVE (CVSS 10.0) and wanted to inquire about any possible dependencies for the (2.53.0) x64 version of Git for Windows and any fix perspective. Given Git is not a Google tool it should be quick to decide and respond to.

The CVE relates to packet crypto/tls in the standard library of Go (Golang). Impacted software: Go-versions prior to 1.26.0-rc.1 plus distros based on it (e.g. Debian Bullseye/Bookworm, RHEL 10, Ubuntu).

How can we ensure the latest Git version is not or no longer impacted by this CV?

Kind regards Jan.Matthiesen@bwi.de

Message 1 of 1 in “Git for Win - CVE-2025-68121 - Impact Analysis and Fix”
  1. Matthiesen, JanFeb 26, 2026

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.