Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
7.5

Git LFS (Large File Storage) on Red Hat Systems Allows Unauthorized File Access

RHSA-2026:4164
Summary

A security update is available for Git LFS on Red Hat systems, which fixes a weakness that could allow attackers to access files they shouldn't. This issue affects Red Hat systems using Git LFS, and you should update your software to the latest version to ensure security.

What to do
  • Update redhat git-lfs to version 0:3.6.1-7.el10_1.
  • Update redhat git-lfs-debuginfo to version 0:3.6.1-7.el10_1.
  • Update redhat git-lfs-debugsource to version 0:3.6.1-7.el10_1.
Affected software
VendorProductAffected versionsFix available
redhat git-lfs <= 0:3.6.1-7.el10_1 0:3.6.1-7.el10_1
redhat git-lfs-debuginfo <= 0:3.6.1-7.el10_1 0:3.6.1-7.el10_1
redhat git-lfs-debugsource <= 0:3.6.1-7.el10_1 0:3.6.1-7.el10_1
Original title
Red Hat Security Advisory: git-lfs security update
osv CVSS3.1 7.5
Published: 10 Mar 2026 · Updated: 13 Mar 2026 · First seen: 10 Mar 2026