版本发布 8
Changes since Git for Windows v2.52.0 (November 17th 2025) ### New Features * Comes with [Git v2.53.0](https://github.com/git/git/blob/v2.53.0/Documentation/RelNotes/2.53.0.adoc). * Pressing the Tab key in an empty line in Git Bash [no longer causes the session to "freeze"](https://github.com/git-for-windows/build-extra/pull/657). * Git for Windows' installer is [now built by InnoSetup v6.6.1](https://github.com/git-for-windows/build-extra/pull/660). * Comes with [cURL v8.18.0](https://curl.se/changes.html#8_18_0). * [Microsoft Edit](https://learn.microsoft.com/en-us/windows/edit/) can [now be specified](https://github.com/git-for-windows/build-extra/pull/669) as Git editor. * Comes with [Git Credential Manager v2.7.0](https://github.com/git-ecosystem/git-credential-manager/releases/tag/v2.7.0), the "anniversary release" after one release-less year, which brings native x64 and ARM64 binaries for the respective flavors of Git for Windows. * [Upgrades](https://github.com/git-for-windows/git/pull/6048) the [memory allocator `mimalloc`](https://microsoft.github.io/mimalloc/) that is used by Git for Windows to v2.2.7. * Comes with the MSYS2 runtime (Git for Windows flavor) based on [Cygwin v3.6.6](https://inbox.sourceware.org/cygwin-announce/20260109194027.293669-1-corinna-cygwin@cygwin.com/). * Comes with [OpenSSL v3.5.5](https://www.openssl.org/news/openssl-3.5-notes.html). ### Bug Fixes * The installer of Git for Windows v2.52 [showed clipped text in some setups](https://github.com/git-for-windows/git/issues/5961), which was fixed. * When calling Microsoft Store apps, their standard I/O is now [set up correctly](https://github.com/git-for-windows/msys2-runtime/pull/122) (meaning: You can call an interactive Python interpreter without the `winpty` hack mentioned in the release notes' Known Issues). * The `astextplain` tool (which is used by Git for Windows to generate diffs of `.pdf` and `.doc` files) used to handle empty files gracefully. This behavior is [now reinstated](https://github.com/git-for-windows/build-extra/pull/668). Filename | SHA-256 -------- | ------- Git-2.53.0-64-bit.exe | 3b4e1b127dbebea2931f2ae9dfafa0c2343a488a1222009debfe78d5d335e6a9 Git-2.53.0-arm64.exe | 8eb369bd00582699da1b9afff4e99dc92e8ce984200b424e8b058d79152eb61d PortableGit-2.53.0-64-bit.7z.exe | 08713a710ec91ac90de1c09f861289a3b103175f098676e5e664c04dd6c6bf23 PortableGit-2.53.0-arm64.7z.exe | dc59b7383104d57110e370638854cc1b1fd50de0fa6d293dc941f35094594298 MinGit-2.53.0-64-bit.zip | 82b562c918ec87b2ef5316ed79bb199e3a25719bb871a0f10294acf21ebd08cd MinGit-2.53.0-arm64.zip | dd03826524767f228c9131bc4b2f4d29bc6f550a39fef9bec240f3e312210a1d MinGit-2.53.0-32-bit.zip | ecdac7d32670aad730222eccf389a7e07803b7716728d9473d3afc24dc098113 MinGit-2.53.0-busybox-64-bit.zip | 5b0acffe1d1aab3c5d99884aba5858a89300076f2d1cba906ea1350a3873aad8 MinGit-2.53.0-busybox-32-bit.zip | 9e4c6523c684558973169071e4a6a3ec5acf0f94a353a5e3f00914672ff72b2e Git-2.53.0-64-bit.tar.bz2 | d0a44fba2cc47e053ed987584d8392675c12a1465690ad1a36f09743a2ffe15e Git-2.53.0-arm64.tar.bz2 | 30e958eeb59c7f481a56551bcd3633a643b9ff1ef024aac3254c478b0e6d4182
Changes since Git for Windows v2.52.0 (November 17th 2025) ### New Features * Comes with [Git v2.53.0-rc2](https://github.com/git/git/blob/v2.53.0-rc2/Documentation/RelNotes/2.53.0.adoc). * Pressing the Tab key in an empty line in Git Bash [no longer causes the session to "freeze"](https://github.com/git-for-windows/build-extra/pull/657). * Git for Windows' installer is [now built by InnoSetup v6.6.1](https://github.com/git-for-windows/build-extra/pull/660). * Comes with [cURL v8.18.0](https://curl.se/changes.html#8_18_0). * [Microsoft Edit](https://learn.microsoft.com/en-us/windows/edit/) can [now be specified](https://github.com/git-for-windows/build-extra/pull/669) as Git editor. * Comes with [Git Credential Manager v2.7.0](https://github.com/git-ecosystem/git-credential-manager/releases/tag/v2.7.0), the "anniversary release" after one release-less year, which brings native x64 and ARM64 binaries for the respective flavors of Git for Windows. * [Upgrades](https://github.com/git-for-windows/git/pull/6048) the [memory allocator `mimalloc`](https://microsoft.github.io/mimalloc/) that is used by Git for Windows to v2.2.7. * Comes with the MSYS2 runtime (Git for Windows flavor) based on [Cygwin v3.6.6](https://inbox.sourceware.org/cygwin-announce/20260109194027.293669-1-corinna-cygwin@cygwin.com/). * Comes with [OpenSSL v3.5.5](https://www.openssl.org/news/openssl-3.5-notes.html). ### Bug Fixes * The installer of Git for Windows v2.52 [showed clipped text in some setups](https://github.com/git-for-windows/git/issues/5961), which was fixed. * When calling Microsoft Store apps, their standard I/O is now [set up correctly](https://github.com/git-for-windows/msys2-runtime/pull/122) (meaning: You can call an interactive Python interpreter without the `winpty` hack mentioned in the release notes' Known Issues). * The `astextplain` tool (which is used by Git for Windows to generate diffs of `.pdf` and `.doc` files) used to handle empty files gracefully. This behavior is [now reinstated](https://github.com/git-for-windows/build-extra/pull/668). Filename | SHA-256 -------- | ------- Git-2.53.0-rc2-64-bit.exe | 8d04f1be821342971d0b0b21e6c5345298849b69f0be018e93c770f027429fa5 Git-2.53.0-rc2-arm64.exe | 8abca21317aa6686e951a7adf18badb7c99d08b92cf3c126fcb96f1765e52482 PortableGit-2.53.0-rc2-64-bit.7z.exe | 24668b9ab15bb83becc0b6c2aecb622236473be741b5b6de94aa678008f9189f PortableGit-2.53.0-rc2-arm64.7z.exe | ef8dd7c8b3583e62786ed491c5daa9294bccc3d03b583d3bccc40c7c2942df65 MinGit-2.53.0-rc2-64-bit.zip | b2b148f2489e1cc93ccf8f12ef67266b60e45790b59b0438ca700cd2c54226ea MinGit-2.53.0-rc2-arm64.zip | b719fac6ec206b029270bdbf6a5ea9a301897adc69093d30fcc0ccfd3dcd76ef MinGit-2.53.0-rc2-32-bit.zip | 52ca2e283cd20acbdb03628e6067dc5e83c56d884c7ea315fdd7e383532b07c5 MinGit-2.53.0-rc2-busybox-64-bit.zip | 343b9859def91cef588c50d279c18bd7fb8406a87c9ab85890ed2415d512eed9 MinGit-2.53.0-rc2-busybox-32-bit.zip | 4f7bd12a9979eb13d490c6136468be16c6a789fbbaf775bff7420b2f8d3fd5bf Git-2.53.0-rc2-64-bit.tar.bz2 | 6087e25459b821df57294cd905a3a2e5f4403f132c5508b50983a0d3c5f294f9 Git-2.53.0-rc2-arm64.tar.bz2 | e4bb529efa52cb759e1c72b53d9ade65a5774eebba723b52eefd7aec074c1620
Changes since Git for Windows v2.51.2 (October 28th 2025) As announced in several recent release notes, [`git svn` is no longer supported by the Git for Windows project](https://github.com/git-for-windows/git/issues/5405). ### New Features * Comes with [Git v2.52.0-rc2](https://github.com/git/git/blob/v2.52.0-rc2/Documentation/RelNotes/2.52.0.adoc). * Comes with [PCRE2 v10.47](https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-10.47). * Comes with [cURL v8.17.0](https://curl.se/changes.html#8_17_0). * The Git for Windows installer is [now built](https://github.com/git-for-windows/build-extra/pull/655) with [version 6.6.0](https://jrsoftware.org/files/is6-whatsnew.htm#:~:text=6.6.0) of InnoSetup, giving it a more modern look. Filename | SHA-256 -------- | ------- Git-2.52.0-rc2-64-bit.exe | e25c0eb211c093adc3a23b6c668a146a61896f81d84b30cebe3e9cadd2396efe Git-2.52.0-rc2-arm64.exe | c99c4cf3d91ea29a2eefa49603e051782fda6f378de6f4b385236984026b88b9 PortableGit-2.52.0-rc2-64-bit.7z.exe | 326b0d3fda15522cbe15c06f2b09fa088a9df9270579ebfd18aefb5ac60f8cbb PortableGit-2.52.0-rc2-arm64.7z.exe | 47003eb65bf34fa1929189d4571e43a307a15b01210957236e4a25420517ffa3 MinGit-2.52.0-rc2-64-bit.zip | e5e0f1d89256c7dd63b4132688ac7dc6034dc8252857c3e0c33d7d673063acf1 MinGit-2.52.0-rc2-arm64.zip | 92097c06ebbd5b3c28449fd13f03220f7bc4ff49240185a7ae4a8caf52864529 MinGit-2.52.0-rc2-32-bit.zip | 1e2c8eb4f5e06b2a3b33fd882563bc12679436a4fc59b5ce7ed2252014950917 MinGit-2.52.0-rc2-busybox-64-bit.zip | 4a626dc900364de41fdfeeff4adaa70361d32e7daa65d929349b3482b54c4fef MinGit-2.52.0-rc2-busybox-32-bit.zip | b103a371e93e364ddf5d738e0af63a6280afe42f072462be3370c7df3bbb7477 Git-2.52.0-rc2-64-bit.tar.bz2 | 8ccf466bb7a862a1e1789aaa8d5c5532c3431a2d1b61d59d18f695cffaf8c2c7 Git-2.52.0-rc2-arm64.tar.bz2 | 033e4a862d4fd7b9aab62979dc36f0d679d6f24e713c136e61a2c96b02abb354
Changes since Git for Windows v2.51.2 (October 28th 2025) As announced in several recent release notes, [`git svn` is no longer supported by the Git for Windows project](https://github.com/git-for-windows/git/issues/5405). ### New Features * Comes with [Git v2.52.0-rc0](https://github.com/git/git/blob/v2.52.0-rc0/Documentation/RelNotes/2.52.0.adoc). * * Comes with [PCRE2 v10.47](https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-10.47). Filename | SHA-256 -------- | ------- Git-2.52.0-rc0-64-bit.exe | 7a351e41ef77ee47d400647048f53017b052c7d0ee7ee559d9a1126c5e9ee17e Git-2.52.0-rc0-arm64.exe | 451b8bec6e6768f38c6b5eaa681d3b479c0c901a68a156036d94ae883beeeff9 PortableGit-2.52.0-rc0-64-bit.7z.exe | ac9b255907daa9da8386e76555d2d7e8b5259c8541c2006301f19aa9da2a8d9e PortableGit-2.52.0-rc0-arm64.7z.exe | 1da1452688e993a69aa635d468b50f867677f9174a080b98cf3d8d4a47803cb8 MinGit-2.52.0-rc0-64-bit.zip | 6fe1281a7f536317602e1a2c31db74d13e028dd7cc4277e634b37831e51a546c MinGit-2.52.0-rc0-arm64.zip | 51127ee62b193aa1e00cff46349cca681f9f7a2eef0df0b7edc5082372e0d45d MinGit-2.52.0-rc0-32-bit.zip | 7e1ee4bc49f8082a2ba873c14a39258f049db0566fb73bd1dc7ceda81ef391ba MinGit-2.52.0-rc0-busybox-64-bit.zip | eb19795e76b0d08b5e88b0413cf5ecd6479e8bec074efe20701e22e11f688bd9 MinGit-2.52.0-rc0-busybox-32-bit.zip | de6c3b2b5c8dc791345b4a2a792044f1d8a8f6038216970188074fc1ae5f9d8e Git-2.52.0-rc0-64-bit.tar.bz2 | f38cfbdac8af7bcff6803b63acf39b176691921663167fc486e17c71379c439e Git-2.52.0-rc0-arm64.tar.bz2 | 709682df4414b82d38b572d56c6764be0bfe30b172034d74b45b28d96e0da04c
Changes since Git for Windows v2.51.0 (August 19th 2025) ### New Features * Comes with [PCRE2 v10.46](https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-10.46). * Comes with [cURL v8.16.0](https://curl.se/changes.html#8_16_0). This addresses [a bug where fetches/pushes could fail with `failed to read data from server: SEC_E_CONTEXT_EXPIRED (0x80090317)` under certain circumstances](https://github.com/git-for-windows/git/issues/5838). Also included: a [back-port of a fix](https://github.com/git-for-windows/MINGW-packages/pull/163) for a bug where connection failures were mistakenly reported as time-outs. * Comes with [Tig v2.6.0](https://github.com/jonas/tig/releases/tag/tig-2.6.0). * Comes with [MinTTY v3.8.1](https://github.com/mintty/mintty/releases/tag/3.8.1). * Comes with [OpenSSL v3.5.3](https://www.openssl.org/news/openssl-3.5-notes.html). ### Bug Fixes * The auto-updater now shows Git for Windows icon in the notification [also on Windows/ARM64](https://github.com/git-for-windows/build-extra/pull/644). * `git clone`/`git fetch` now deals more gracefully with directory / file conflicts when the files backend is used for ref storage, by failing only the ones that are involved in the conflict while allowing others. This is a regression in Git v2.51.0 that was [reported in Git for Windows](https://github.com/git-for-windows/git/issues/5804) and independently also [to the Git mailing list](https://lore.kernel.org/git/YQXPR01MB3046197EF39296549EE6DD669A33A@YQXPR01MB3046.CANPRD01.PROD.OUTLOOK.COM/). This was fixed by merging Git's topic branch [`kn/refs-files-case-insensitive`](https://github.com/gitgitgadget/git/commits/kn/refs-files-case-insensitive). * Support for pathspecs in `diff --no-index` [was somewhat buggy](https://github.com/git-for-windows/issues/5836), which has been fixed. * `git sparse-checkout` subcommand learned a new `clean` action to prune otherwise unused working-tree files that are outside the areas of interest. An earlier version of this had been [integrated into Microsoft Git already](https://github.com/microsoft/git/pull/796). This was fixed by merging Git's topic branch [`ds/sparse-checkout-clean`](https://github.com/gitgitgadget/git/commits/ds/sparse-checkout-clean). * `git rebase -i` failed to clean-up the commit log message when the command commits the final one in a chain of "fixup" commands, which has been corrected. Backported from Git's topic branch [`pw/rebase-i-cleanup-fix`](https://github.com/gitgitgadget/git/commits/pw/rebase-i-cleanup-fix). * `git subtree` did not work correctly when splitting squashed subtrees, which has been improved. Backported from Git's topic branch [`cs/subtree-squash-split-fix`](https://github.com/gitgitgadget/git/commits/cs/subtree-squash-split-fix). * Some among `git add -p` and friends ignored `color.diff` and/or `color.ui` configuration variables, which is an old regression, which has been corrected. This was fixed by merging Git's topic branch [`jk/add-i-color`](https://github.com/gitgitgadget/git/commits/jk/add-i-color). * A corner-case bug in `git log -L...` has been corrected. This was fixed by merging Git's topic branch [`sg/line-log-boundary-fixes`](https://github.com/gitgitgadget/git/commits/sg/line-log-boundary-fixes). * A broken or malicious `git fetch` can say that it has the same object for many many times, and the upload-pack serving it can exhaust memory storing them redundantly, which has been corrected. This was fixed by merging Git's topic branch [`ps/upload-pack-oom-protection`](https://github.com/gitgitgadget/git/commits/ps/upload-pack-oom-protection). * Fixes multiple crashes around midx write-out codepaths. This was fixed by merging Git's topic branch [`ds/midx-write-fixes`](https://github.com/gitgitgadget/git/commits/ds/midx-write-fixes). * `git repack --path-walk` lost objects in some corner cases, which has been corrected. This was fixed by merging Git's topic branch [`ds/path-walk-repack-fix`](https://github.com/gitgitgadget/git/commits/ds/path-walk-repack-fix). * Under a race against another process that is repacking the repository, especially a partially cloned one, `git fetch` may mistakenly think some objects we do have are missing, which has been corrected. This was fixed by merging Git's topic branch [`jk/fetch-check-graph-objects-fix`](https://github.com/gitgitgadget/git/commits/jk/fetch-check-graph-objects-fix). * Various options to `git diff` that makes comparison ignore certain aspects of the differences (like "space changes are ignored", "differences in lines that match these regular expressions are ignored") did not work well with `--name-only` and friends. This was fixed by merging Git's topic branch [`ly/diff-name-only-with-diff-from-content`](https://github.com/gitgitgadget/git/commits/ly/diff-name-only-with-diff-from-content). * `git diff --no-index` run inside a subdirectory under control of a Git repository operated at the top of the working tree and stripped the prefix from the output, and oddballs like "-" (stdin) did not work correctly because of it. Correct the set-up by undoing what the set-up sequence did to the current working directory and prefix. This was fixed by merging Git's topic branch [`jc/diff-no-index-in-subdir`](https://github.com/gitgitgadget/git/commits/jc/diff-no-index-in-subdir). * Various bugs about rename handling in "ort" merge strategy have been fixed. This was fixed by merging Git's topic branch [`en/ort-rename-fixes`](https://github.com/gitgitgadget/git/commits/en/ort-rename-fixes). * `git push` had a code path that led to `BUG()` but it should have reported a regular failure, as it is a response to a usual but invalid end-user action to attempt pushing an object that does not exist. This was fixed by merging Git's topic branch [`dl/push-missing-object-error`](https://github.com/gitgitgadget/git/commits/dl/push-missing-object-error). * `git refs migrate` to migrate the reflog entries from a refs backend to another had a handful of bugs squashed. This was fixed by merging Git's topic branch [`ps/reflog-migrate-fixes`](https://github.com/gitgitgadget/git/commits/ps/reflog-migrate-fixes). * During interactive rebase, using `drop` on a merge commit lead to an error, which was incorrect. This was fixed by merging Git's topic branch [`js/rebase-i-allow-drop-on-a-merge`](https://github.com/gitgitgadget/git/commits/js/rebase-i-allow-drop-on-a-merge). Filename | SHA-256 -------- | ------- Git-2.51.0.2-64-bit.exe | 5cf583441ccd8d98d3492936235b6ee30c6847d1b3f49365d6a025b3432094ad Git-2.51.0.2-arm64.exe | ba95adc559e2d91ae28aa354c0ffb06b2c54f2bf42985f278dded9ca31194816 PortableGit-2.51.0.2-64-bit.7z.exe | 85d6e9f865b73827e22d532fd6cd5b93987c8d264142786b0721956619d5c00e PortableGit-2.51.0.2-arm64.7z.exe | f35e795224349c63b7d6c429c2d8404a6ce7e2e8f91934a3f6ba2ca8e7e285a8 MinGit-2.51.0.2-64-bit.zip | 314fc2b7425ca116ea201e493fcb72008376c64997e866e6c8b8a5b360b3b8a9 MinGit-2.51.0.2-arm64.zip | 4feecfaea2647a2a0b25b7bfa518b9a65eb3434d9be7016e4dd348f07bcc6d2f MinGit-2.51.0.2-32-bit.zip | 617a1433fbf5e23deaa17b7559d79f465a08fea7e09a0cff32ac0f2216003a8e MinGit-2.51.0.2-busybox-64-bit.zip | deb7e15ec1e33cad225a6be4401617e21569d188da0a1ca71c29d8018ad087b6 MinGit-2.51.0.2-busybox-32-bit.zip | b2ed51815e858497c2399004a855d5ebb0f8eacd93e0a81a6afc46b5741efda6 Git-2.51.0.2-64-bit.tar.bz2 | 0e4dcabc37f9749fb57b292611a53155842fe52bcbef8e7f56cc80ced65bf3f5 Git-2.51.0.2-arm64.tar.bz2 | a219d91f5f8e707f5e7ff23402af1e7e6421c972896fa3f33edba170439bae90
Changes since Git for Windows v2.50.1 (July 8th 2025) ### New Features * Comes with [Git v2.51.0](https://github.com/git/git/blob/v2.51.0/Documentation/RelNotes/2.51.0.adoc). * The Portable Git installers (which are self-extracting 7-Zip archives) are now based off of [7-Zip 25.01](https://sourceforge.net/p/sevenzip/discussion/45797/thread/da14cd780b/) * Comes with [cURL v8.15.0](https://curl.se/changes.html#8_15_0). * Comes with the MSYS2 runtime (Git for Windows flavor) based on [Cygwin v3.6.4](https://cygwin.com/pipermail/cygwin-announce/2025-July/012416.html). * Comes with [MinTTY v3.7.9](https://github.com/mintty/mintty/releases/tag/3.7.9). Filename | SHA-256 -------- | ------- Git-2.51.0-64-bit.exe | 843037416371600a7f289be8fe2b2224afe1c1bb0736bbab7b3ff393e6a7aaf2 Git-2.51.0-arm64.exe | 739673a52a2ea5a3ac23ef1a74985647fd21a758e5e177fed2d995dd897a1600 PortableGit-2.51.0-64-bit.7z.exe | a09b275d51ed3e829128e04cf4168fb54896cf6234bb30fecb8dc96a2bd321fa PortableGit-2.51.0-arm64.7z.exe | 0aacd4edf0c1715334a18725a947584652e1b34bddab63ac3f4a82c9f7c78e38 MinGit-2.51.0-64-bit.zip | c2c955a21fa99889d83f485f24fa5d9a38fffc2d509d4022385510e11c26b250 MinGit-2.51.0-arm64.zip | b21755ccd10f71a37ec341ca9ac450cebee71bb1e70c0d88d90ddd6e5b16dfa4 MinGit-2.51.0-32-bit.zip | 5a8f1cace31a817fa9fa3d18146e8b40a28fd365d48958976df93ae6f0bae077 MinGit-2.51.0-busybox-64-bit.zip | 6b71de89d321310d1cc233565a10b06cabc65582e1c37bae47548c1fa323c878 MinGit-2.51.0-busybox-32-bit.zip | 050fe76ece1b7762cd556bdbe242a979d5d769c2072db45e1cc888061552779c Git-2.51.0-64-bit.tar.bz2 | 151bddf70e1115631e62bb05535b5e6726b3813e1f363953ad6b4e6697d96933 Git-2.51.0-arm64.tar.bz2 | 5c3bc6ca50ef6a7686832d2549e6e1b3b1060cf18322a2bbe064d4aec2f33904
Changes since Git for Windows v2.49.0 (March 17th 2025) This is a security fix release, addressing CVE-2024-50349, CVE-2024-52006, CVE-2025-27613, CVE-2025-27614, CVE-2025-46334, CVE-2025-46835, CVE-2025-48384, CVE-2025-48385, and CVE-2025-48386. ### New Features * Comes with [Git v2.49.1](https://github.com/git/git/blob/v2.49.1/Documentation/RelNotes/2.49.1.txt). ### Bug Fixes * [**CVE-2025-27613**](https://github.com/j6t/gitk/security/advisories/GHSA-f3cw-xrj3-wr2v), Gitk: When a user clones an untrusted repository and runs Gitk without additional command arguments, any writable file can be created and truncated. The option "Support per-file encoding" must have been enabled. The operation "Show origin of this line" is affected as well, regardless of the option being enabled or not. * [**CVE-2025-27614**](https://github.com/j6t/gitk/security/advisories/GHSA-g4v5-fjv9-mhhc), Gitk: A Git repository can be crafted in such a way that a user who has cloned the repository can be tricked into running any script supplied by the attacker by invoking `gitk filename`, where `filename` has a particular structure. * [**CVE-2025-46334**](https://github.com/j6t/git-gui/security/advisories/GHSA-7px4-9hg2-fvhx), Git GUI (Windows only): A malicious repository can ship versions of sh.exe or typical textconv filter programs such as astextplain. On Windows, path lookup can find such executables in the worktree. These programs are invoked when the user selects "Git Bash" or "Browse Files" from the menu. * [**CVE-2025-46835**](https://github.com/j6t/git-gui/security/advisories/GHSA-xfx7-68v4-v8fg), Git GUI: When a user clones an untrusted repository and is tricked into editing a file located in a maliciously named directory in the repository, then Git GUI can create and overwrite any writable file. * [**CVE-2025-48384**](https://github.com/git/git/security/advisories/GHSA-vwqx-4fm8-6qc9), Git: When reading a config value, Git strips any trailing carriage return and line feed (CRLF). When writing a config entry, values with a trailing CR are not quoted, causing the CR to be lost when the config is later read. When initializing a submodule, if the submodule path contains a trailing CR, the altered path is read resulting in the submodule being checked out to an incorrect location. If a symlink exists that points the altered path to the submodule hooks directory, and the submodule contains an executable post-checkout hook, the script may be unintentionally executed after checkout. * [**CVE-2025-48385**](https://github.com/git/git/security/advisories/GHSA-m98c-vgpc-9655), Git: When cloning a repository Git knows to optionally fetch a bundle advertised by the remote server, which allows the server-side to offload parts of the clone to a CDN. The Git client does not perform sufficient validation of the advertised bundles, which allows the remote side to perform protocol injection. This protocol injection can cause the client to write the fetched bundle to a location controlled by the adversary. The fetched content is fully controlled by the server, which can in the worst case lead to arbitrary code execution. * [**CVE-2025-48386**](https://github.com/git/git/security/advisories/GHSA-4v56-3xvj-xvfr), Git: The wincred credential helper uses a static buffer (`target`) as a unique key for storing and comparing against internal storage. This credential helper does not properly bounds check the available space remaining in the buffer before appending to it with `wcsncat()`, leading to potential buffer overflows. Filename | SHA-256 -------- | ------- Git-2.49.1-64-bit.exe | 887015706520687bbeecad5de0b651f28dd5b5019d4ad7d698cdc9a33e7c60c3 Git-2.49.1-arm64.exe | 4a57dd0af4d6abb3eb8b66393048372a86283925ae95e9be057338b23d9f1d22 PortableGit-2.49.1-64-bit.7z.exe | 643def94eaa15215ebe1018804d2ac3a458e80a2fc27aef6e5139411728f3a7d PortableGit-2.49.1-arm64.7z.exe | b6e9dc984e9b8c32ad9a5bb801f6909cae2825052b9b0120dc1b130abe07ffdc MinGit-2.49.1-64-bit.zip | 3934292e3467ef4402770a966190112950203b4f3be6d58c37e80bd85bce8ee9 MinGit-2.49.1-arm64.zip | 2c18f00ee5cc01222035a283e314244e38c3ec285cded76817ca2f7572b83992 MinGit-2.49.1-32-bit.zip | d73eddfeca821dd7a55309281f2ee9ea06b5ebec6dc89c6394e977a07901744a MinGit-2.49.1-busybox-64-bit.zip | 1e8ea4d43534229ee11a2fba2cc218dae3182d832766f6df93fcfc1808962ff4 MinGit-2.49.1-busybox-32-bit.zip | 1dcedac61666640f2fa87ec5462a299e35c325bb8a2b4dc25fc9fac1637dcb9c Git-2.49.1-64-bit.tar.bz2 | 2ce022aa1bb833c515b79c52426f3e7a5e8692fab3a2af7eeb9f4062aa70d7b2 Git-2.49.1-arm64.tar.bz2 | 583dfbec6084d9069ff90424b1cdcf3fcc29af8140400c15867990293e74d6c5
Changes since Git for Windows v2.47.1(2) (January 14th 2025) This is a security fix release, addressing CVE-2024-50349, CVE-2024-52006, CVE-2025-27613, CVE-2025-27614, CVE-2025-46334, CVE-2025-46835, CVE-2025-48384, CVE-2025-48385, and CVE-2025-48386. ### New Features * Comes with [Git v2.47.3](https://github.com/git/git/blob/v2.47.3/Documentation/RelNotes/2.47.3.txt). ### Bug Fixes * [**CVE-2025-27613**](https://github.com/j6t/gitk/security/advisories/GHSA-f3cw-xrj3-wr2v), Gitk: When a user clones an untrusted repository and runs Gitk without additional command arguments, any writable file can be created and truncated. The option "Support per-file encoding" must have been enabled. The operation "Show origin of this line" is affected as well, regardless of the option being enabled or not. * [**CVE-2025-27614**](https://github.com/j6t/gitk/security/advisories/GHSA-g4v5-fjv9-mhhc), Gitk: A Git repository can be crafted in such a way that a user who has cloned the repository can be tricked into running any script supplied by the attacker by invoking `gitk filename`, where `filename` has a particular structure. * [**CVE-2025-46334**](https://github.com/j6t/git-gui/security/advisories/GHSA-7px4-9hg2-fvhx), Git GUI (Windows only): A malicious repository can ship versions of sh.exe or typical textconv filter programs such as astextplain. On Windows, path lookup can find such executables in the worktree. These programs are invoked when the user selects "Git Bash" or "Browse Files" from the menu. * [**CVE-2025-46835**](https://github.com/j6t/git-gui/security/advisories/GHSA-xfx7-68v4-v8fg), Git GUI: When a user clones an untrusted repository and is tricked into editing a file located in a maliciously named directory in the repository, then Git GUI can create and overwrite any writable file. * [**CVE-2025-48384**](https://github.com/git/git/security/advisories/GHSA-vwqx-4fm8-6qc9), Git: When reading a config value, Git strips any trailing carriage return and line feed (CRLF). When writing a config entry, values with a trailing CR are not quoted, causing the CR to be lost when the config is later read. When initializing a submodule, if the submodule path contains a trailing CR, the altered path is read resulting in the submodule being checked out to an incorrect location. If a symlink exists that points the altered path to the submodule hooks directory, and the submodule contains an executable post-checkout hook, the script may be unintentionally executed after checkout. * [**CVE-2025-48385**](https://github.com/git/git/security/advisories/GHSA-m98c-vgpc-9655), Git: When cloning a repository Git knows to optionally fetch a bundle advertised by the remote server, which allows the server-side to offload parts of the clone to a CDN. The Git client does not perform sufficient validation of the advertised bundles, which allows the remote side to perform protocol injection. This protocol injection can cause the client to write the fetched bundle to a location controlled by the adversary. The fetched content is fully controlled by the server, which can in the worst case lead to arbitrary code execution. * [**CVE-2025-48386**](https://github.com/git/git/security/advisories/GHSA-4v56-3xvj-xvfr), Git: The wincred credential helper uses a static buffer (`target`) as a unique key for storing and comparing against internal storage. This credential helper does not properly bounds check the available space remaining in the buffer before appending to it with `wcsncat()`, leading to potential buffer overflows. Filename | SHA-256 -------- | ------- MinGit-2.47.3-64-bit.zip | 033b94947b64c53442feefc4fdb0e66dc0ee619904a559627a952336e7a62e31 MinGit-2.47.3-arm64.zip | 4aae1a69de2f029a10438ccd9fa4bf9572b0bcf6f6c6be884f4d2e0acbbaa3aa MinGit-2.47.3-32-bit.zip | 969c2fd5727cd347775b4956e8c344b5decdf23651f4aa558bd0a91aa9562964 MinGit-2.47.3-busybox-64-bit.zip | 1c7f90eae02c8d1936fb88d84149430a41d81569f9751eb8faa11b0a972cc202 MinGit-2.47.3-busybox-32-bit.zip | 407a57301e5c5f8d9d8c139c6b6cf9458ee5e88bc3b7233fccfe5ec86356cdfd