Description
A denial of service (DoS) vulnerability was discovered in go-git versions prior to v5.11. This vulnerability allows an attacker to perform denial of service attacks by providing specially crafted responses from a Git server which triggers resource exhaustion in go-git clients.
Applications using only the in-memory filesystem supported by go-git are not affected by this vulnerability.
This is a go-git implementation issue and does not affect the upstream git cli.
Applications using only the in-memory filesystem supported by go-git are not affected by this vulnerability.
This is a go-git implementation issue and does not affect the upstream git cli.
No analysis available yet.
Remediation
Vendor Solution
An upgrade to v. 5.11 fixes this issue
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-3251 | A denial of service (DoS) vulnerability was discovered in go-git versions prior to v5.11. This vulnerability allows an attacker to perform denial of service attacks by providing specially crafted responses from a Git server which triggers resource exhaustion in go-git clients. Applications using only the in-memory filesystem supported by go-git are not affected by this vulnerability. This is a go-git implementation issue and does not affect the upstream git cli. |
Github GHSA |
GHSA-mw99-9chc-xw7r | Maliciously crafted Git server replies can cause DoS on go-git clients |
References
History
Tue, 17 Jun 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Subscriptions
Status: PUBLISHED
Assigner: Bitdefender
Published:
Updated: 2025-06-17T21:09:18.035Z
Reserved: 2023-11-27T14:21:51.157Z
Link: CVE-2023-49568
Updated: 2025-06-17T21:07:22.529Z
Status : Modified
Published: 2024-01-12T11:15:12.680
Modified: 2024-11-21T08:33:34.447
Link: CVE-2023-49568
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA