Git for Windows is the Windows port of Git. Prior to 2.55.0.windows.4, a malicious remote Git server can advertise a bundle URI that reaches transport_get_remote_bundle_uri(), fetch_bundle_uri_internal(), and copy_uri_to_file() in bundle-uri.c during clone or fetch when transfer.bundleuri=true. Non-HTTP(S) values are treated as local filesystem paths, and file URI prefixes are removed, so a bare UNC path or file URI targeting an attacker-controlled share causes Windows to initiate an outbound SMB connection. This can expose NTLM authentication material to the attacker-selected host. This issue is fixed in version 2.55.0.windows.4.
We have discovered 515 live websites that are affected by CVE-2026-62960.
| 116 websites | |
| 168 websites | |
| 62 websites | |
| 52 websites | |
| 15 websites | |
| 12 websites | |
| 10 websites | |
| 9 websites | |
| 9 websites | |
| 7 websites |
| .org | 135 websites |
| .com | 105 websites |
| .de | 79 websites |
| .net | 52 websites |
| .eu | 9 websites |
| .fr | 8 websites |
| .at | 6 websites |
| .info | 6 websites |
| .org.uk | 6 websites |
| .io | 5 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ****.***********.org | **,*** | ||
| ****.**.cz | **,*** | ||
| ***.********.org | **,*** | ||
| ************.org | **,*** | ||
| ***.*******.org | **,*** | ||
| ****.**.io | ***,*** | ||
| ***.**********.org | ***,*** | ||
| ***.********.org | ***,*** | ||
| *****.***.****.org | ***,*** | ||
| *******.org | ***,*** |
FAQ