A denial of service (DoS) vulnerability was discovered in go-git versions prior to v5.11. This vulnerability allows an attacker to perform denial of service attacks by providing specially crafted responses from a Git server which triggers resource exhaustion in go-git clients.
Applications using only the in-memory filesystem supported by go-git are not affected by this vulnerability.
This is a go-git implementation issue and does not affect the upstream git cli.
Applications using only the in-memory filesystem supported by go-git are not affected by this vulnerability.
This is a go-git implementation issue and does not affect the upstream git cli.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-3251 | A denial of service (DoS) vulnerability was discovered in go-git versions prior to v5.11. This vulnerability allows an attacker to perform denial of service attacks by providing specially crafted responses from a Git server which triggers resource exhaustion in go-git clients. Applications using only the in-memory filesystem supported by go-git are not affected by this vulnerability. This is a go-git implementation issue and does not affect the upstream git cli. |
Github GHSA |
GHSA-mw99-9chc-xw7r | Maliciously crafted Git server replies can cause DoS on go-git clients |
Fixes
Solution
An upgrade to v. 5.11 fixes this issue
Workaround
No workaround given by the vendor.
References
History
Tue, 17 Jun 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Bitdefender
Published:
Updated: 2025-06-17T21:09:18.035Z
Reserved: 2023-11-27T14:21:51.157Z
Link: CVE-2023-49568
Updated: 2025-06-17T21:07:22.529Z
Status : Modified
Published: 2024-01-12T11:15:12.680
Modified: 2024-11-21T08:33:34.447
Link: CVE-2023-49568
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA