← Back

Go Getter

go-getter

Vendor: Hashicorp • 9 CVEs

CVEs (9)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Hashicorp
1Go Getter
Jun 17, 2026
Aug 15, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
HashiCorp's go-getter library subdirectory download feature is vulnerable to symlink attacks leading to unauthorized read access beyond the designated directory boundaries. This vulnerability, identified as CVE-2025-8959...Show more
HashiCorp's go-getter library subdirectory download feature is vulnerable to symlink attacks leading to unauthorized read access beyond the designated directory boundaries. This vulnerability, identified as CVE-2025-8959, is fixed in go-getter 1.7.9.Show less
1Hashicorp
1Go Getter
Jun 17, 2026
Jun 25, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
HashiCorp’s go-getter library can be coerced into executing Git update on an existing maliciously modified Git Configuration, potentially leading to arbitrary code execution.
1Hashicorp
1Go Getter
Jun 17, 2026
Apr 17, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
HashiCorp’s go-getter library is vulnerable to argument injection when executing Git to discover remote branches. This vulnerability does not affect the go-getter/v2 branch and package.
1Hashicorp
1Go Getter
Jun 17, 2026
Feb 16, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
HashiCorp go-getter up to 1.6.2 and 2.1.1 is vulnerable to decompression bombs. Fixed in 1.7.0 and 2.2.0.
1Hashicorp
1Go Getter
Jun 17, 2026
May 25, 2022
N/A· v4
8.6 HIGH· v3
7.5 HIGH· v2
go-getter up to 1.5.11 and 2.0.2 panicked when processing password-protected ZIP files. Fixed in 1.6.1 and 2.1.0.
1Hashicorp
1Go Getter
Jun 17, 2026
May 25, 2022
N/A· v4
8.6 HIGH· v3
7.5 HIGH· v2
go-getter up to 1.5.11 and 2.0.2 allowed asymmetric resource exhaustion when go-getter processed malicious HTTP responses. Fixed in 1.6.1 and 2.1.0.
1Hashicorp
1Go Getter
Jun 17, 2026
May 25, 2022
N/A· v4
8.6 HIGH· v3
7.5 HIGH· v2
go-getter up to 1.5.11 and 2.0.2 allowed arbitrary host access via go-getter path traversal, symlink processing, and command injection flaws. Fixed in 1.6.1 and 2.1.0.
1Hashicorp
1Go Getter
Jun 17, 2026
May 25, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
go-getter up to 1.5.11 and 2.0.2 allowed protocol switching, endless redirect, and configuration bypass via abuse of custom HTTP response header processing. Fixed in 1.6.1 and 2.1.0.
1Hashicorp
1Go Getter
Jun 17, 2026
Apr 27, 2022
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
The Hashicorp go-getter library before 1.5.11 does not redact an SSH key from a URL query parameter.