A vulnerability labeled as problematic has been found in go-git up to 5.17.x/6.0.0-alpha.1. The affected element is an unknown function. The manipulation results in insufficiently protected credentials.
This vulnerability was named CVE-2026-41506. The attack may be performed from remote. There is no available exploit.
The affected component should be upgraded.