Back to vendor advisories
Microsoft Security Response CenterCVE-2026-32631

GitHub: CVE-2026-32631 'git clone' from manipulated repositories can leak NTLM hashes

CVE-2026-32631 is regarding a vulnerability where it is possible to obtain a user's NTLM hash by tricking them into cloning a malicious repository, or checking out a malicious branch that accesses an attacker-controlled server. By default, NTLM authentication does not need any user interaction. GitHub created this CVE on their behalf. The documented Visual Studio updates incorporate updates in Git which address this vulnerability. Please see CVE-2026-32631 for more information.

7.4CVSS out of 10High severity
Scope

What the vendor says is affected

  • Microsoft Visual Studio 2019 version 16.4 (includes 16.0 - 16.3)
  • Microsoft Visual Studio 2017 version 15.9 (includes 15.0 - 15.8)
  • Microsoft Visual Studio 2022 version 17.12
  • Microsoft Visual Studio 2022 version 17.14
  • Microsoft Visual Studio 2026 version 18.4

Versions the vendor lists as fixed

  • 16.11.55
  • 15.9.79
  • 17.12.19
  • 17.14.30
  • 18.4.4
Next step

What the vendor recommends

Release Notes

Review the complete instructions on the vendor's site
Timeline

When this advisory changed

  1. Published by Microsoft Security Response Center

    The publication date reported by the vendor.

  2. Added to SecurityAlert

    We collected the advisory from the official source.

Vulnerabilities

CVEs named in this advisory