CLEANSTART-2026-XC26421
Dashboard / Vulnerabilities / CLEANSTART-2026-XC26421
CLEANSTART-2026-XC26421
Summary: Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection
Details: Multiple security vulnerabilities affect the git-lfs package. Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. See references for individual vulnerability details.
References: https://github.com/cleanstart-dev/cleanstart-security-advisories/tree/main/advisories/2026/CLEANSTART-2026-XC26421.json, https://osv.dev/vulnerability/CVE-2021-38561, https://osv.dev/vulnerability/CVE-2022-27191, https://osv.dev/vulnerability/CVE-2026-46600, https://osv.dev/vulnerability/CVE-2026-56855, https://osv.dev/vulnerability/CVE-2026-78662, https://nvd.nist.gov/vuln/detail/CVE-2021-38561, https://nvd.nist.gov/vuln/detail/CVE-2022-27191, https://nvd.nist.gov/vuln/detail/CVE-2026-46600, https://nvd.nist.gov/vuln/detail/CVE-2026-56855, https://nvd.nist.gov/vuln/detail/CVE-2026-78662
Affected packages
Package
Name: git-lfs
Purl:
Affected ranges
Type: ECOSYSTEM
Events:
