PT-2023-31260 · Go-Git+3 · Go-Git+3
Bdilalu
+1
·
Published
2023-12-27
·
Updated
2026-03-12
·
CVE-2023-49568
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
go-git versions prior to v5.11
Description
A denial of service (DoS) vulnerability was discovered in go-git. This vulnerability allows an attacker to perform denial of service attacks by providing specially crafted responses from a Git server, which triggers resource exhaustion in go-git clients. Applications using only the in-memory filesystem supported by go-git are not affected by this vulnerability. This is a go-git implementation issue and does not affect the upstream git cli.
Recommendations
For go-git versions prior to v5.11, upgrade to v5.11 to mitigate this vulnerability.
As a temporary workaround, consider limiting the use of go-git to only trustworthy Git servers if upgrading to v5.11 is not possible.
Fix
DoS
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Debian
Linuxmint
Ubuntu
Go-Git