PT-2023-31260 · Go-Git+3 · Go-Git+3

Bdilalu

+1

·

Published

2023-12-27

·

Updated

2026-03-12

·

CVE-2023-49568

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions go-git versions prior to v5.11
Description A denial of service (DoS) vulnerability was discovered in go-git. This vulnerability allows an attacker to perform denial of service attacks by providing specially crafted responses from a Git server, which triggers resource exhaustion in go-git clients. Applications using only the in-memory filesystem supported by go-git are not affected by this vulnerability. This is a go-git implementation issue and does not affect the upstream git cli.
Recommendations For go-git versions prior to v5.11, upgrade to v5.11 to mitigate this vulnerability. As a temporary workaround, consider limiting the use of go-git to only trustworthy Git servers if upgrading to v5.11 is not possible.

Fix

DoS

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-33892
AZL-35095
AZL-39595
CVE-2023-49568
GHSA-MW99-9CHC-XW7R
GO-2024-2466
RHSA-2024:0880
RHSA-2024:3925
USN-8088-1

Affected Products

Debian
Linuxmint
Ubuntu
Go-Git