Changes since Git for Windows v2.52.0 (November 17th 2025)
This is a security fix release, addressing CVE-2025-66413.
- CVE-2025-66413, Git for Windows: When a user clones a repository from an attacker-controlled server, Git may attempt NTLM authentication and disclose the user's NTLMv2 hash to the remote server. Since NTLM hashing is weak, the captured hash can potentially be brute-forced to recover the user's credentials. This is addressed by disabling NTLM authentication by default.
| Filename | SHA-256 |
|---|---|
| MinGit-2.52.0.2-64-bit.zip | 5956d3df3cfe9b95bc241b02c0efcaf3bcc11543ddd426d53bc9be22e5d6d931 |
| MinGit-2.52.0.2-arm64.zip | a83320bdd9cfa425ee111a01961ed0e4c2bd6e84d2aeb860e0b907faa62ed392 |
| MinGit-2.52.0.2-32-bit.zip | 5da7b126796651ef705647c223a3e00fc6eb964f80310ed0b39e61a754d73737 |
| MinGit-2.52.0.2-busybox-64-bit.zip | d666f540114e8e9ade81a741e37f524241e97116c4e8e709176eb87d4a669dc1 |
| MinGit-2.52.0.2-busybox-32-bit.zip | 79a0e15e0cd76a643576ce0c118e9719fafc0f6528285ce19e1eaa91ad80718b |