CVE-2026-62960

Git for Windows: Server-advertised bundle-uri can trigger outbound SMB callbacks via UNC and file:// paths on Windows

Git for Windows is the Windows port of Git. Prior to 2.55.0.windows.4, a malicious remote Git server can advertise a bundle URI that reaches transport_get_remote_bundle_uri(), fetch_bundle_uri_internal(), and copy_uri_to_file() in bundle-uri.c during clone or fetch when transfer.bundleuri=true. Non-HTTP(S) values are treated as local filesystem paths, and file URI prefixes are removed, so a bare UNC path or file URI targeting an attacker-controlled share causes Windows to initiate an outbound SMB connection. This can expose NTLM authentication material to the attacker-selected host. This issue is fixed in version 2.55.0.windows.4.


We have discovered 515 live websites that are affected by CVE-2026-62960.

Run a Free Instant Scan




Affected Software

Product  git
Category Dev Tools
Vulnerable Domains515 live websites (100% of git install base)
Vulnerable Versions
  • from 0 through 2.55
Vulnerable Versions Count31 versions ( 100% of all versions)


Common Weakness Enumeration

CWE-200 Exposure of Sensitive Information to an Unauthorized Actor



Details

  • Published - Aug 21, 2026
  • Updated - Aug 26, 2026

Website Distribution by Country

Number of websites using CVE-2026-62960
United States116 websites



Germany168 websites
Singapore62 websites
France52 websites
GB15 websites
Netherlands12 websites
Austria10 websites
Switzerland9 websites
Denmark9 websites
Australia7 websites

Website Distribution by TLD

Number of websites using CVE-2026-62960
.org135 websites
.com105 websites
.de79 websites
.net52 websites
.eu9 websites
.fr8 websites
.at6 websites
.info6 websites
.org.uk6 websites
.io5 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-62960

Top websites that are affected by CVE-2026-62960. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
****.***********.org United States**,***
****.**.cz Germany**,***
***.********.org France**,***
************.org United States**,***
***.*******.org United States**,***
****.**.io Finland***,***
***.**********.org Austria***,***
***.********.org United States***,***
*****.***.****.org United States***,***
*******.org France***,***
See full domain list

FAQ

CVE-2026-62960 is Exposure of Sensitive Information to an Unauthorized Actor in git
A total of 515 websites have been identified as vulnerable to CVE-2026-62960, based on global website indexing conducted by WebTechSurvey.
The git is affected by the CVE-2026-62960 vulnerability.
git versions up to and including 2.55 are vulnerable to CVE-2026-62960.