Wiz Agents & Workflows are here

CVE-2026-33762
Packer vulnerability analysis and mitigation

Impact

go-git’s index decoder for format version 4 fails to validate the path name prefix length before applying it to the previously decoded path name. A maliciously crafted index file can trigger an out-of-bounds slice operation, resulting in a runtime panic during normal index parsing. This issue only affects Git index format version 4. Earlier formats (go-git supports only v2 and v3) are not vulnerable to this issue. An attacker able to supply a crafted .git/index file can cause applications using go-git to panic while reading the index. If the application does not recover from panics, this results in process termination, leading to a denial-of-service (DoS) condition. Exploitation requires the ability to modify or inject a Git index file within the local repository in disk. This typically implies write access to the .git directory.

Patches

Users should upgrade to v5.17.1, or the latest v6 pseudo-version, in order to mitigate this vulnerability.

Credit

go-git maintainers thank @kq5y for finding and reporting this issue privately to the go-git project.


SourceNVD

Related Packer vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-33186CRITICAL9.1
  • cAdvisorcAdvisor
  • kube-vip-cloud-provider-0.0.10
NoYesMar 20, 2026
CVE-2026-27142MEDIUM6.1
  • cAdvisorcAdvisor
  • secrets-store-csi-driver
NoYesMar 06, 2026
CVE-2026-34165MEDIUM5
  • PackerPacker
  • grype
NoYesMar 30, 2026
CVE-2026-33762LOW2.8
  • PackerPacker
  • bom
NoYesMar 30, 2026
CVE-2026-27139LOW2.5
  • cAdvisorcAdvisor
  • terraform-provider-sendgrid-fips
NoYesMar 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management