CVE-2026-93326
Description
A build step for a Git source, crafted in a specific way, can bypass some policy validation rules. A malicious build definition can make the repository look like it is coming from a different remote URL than it really is when Git clone is happening. If policy is doing more stricter validation, for example based on commit SHA, commit data, or signatures, then all these validations still apply correctly.
Is your site exposed to CVE-2026-93326?
Run a free security scan — no signup, results in seconds.
Weakness Type (CWE)
References
Frequently Asked Questions
What is CVE-2026-93326? +
How do I check if I'm vulnerable to CVE-2026-93326? +
Related Vulnerabilities
Incorrect Behavior Order: Validate Before Canonicalize vulnerability in ash-project ash lets an attacker store a case-insensitive string value that violates …
`zip` is a zip library for rust which supports reading and writing of simple ZIP files. In the archive extraction …
The cohttp package before 6.3.0 for OCaml allows directory traversal.
go-git is an extensible git implementation library written in pure Go. Prior to 5.19.0 and 6.0.0-alpha.3, go-git may parse malformed …
PeaZip before 11.3.0, in a non-default configuration, is vulnerable to OS command injection via a filename in an archive because …
Incorrect Behavior Order: Validate Before Canonicalize in the report theme CSS sanitizer in maalfer Pentestify 1.2.0 through 2.3.2 allows an …