A denial of service (DoS) vulnerability was discovered in go-git versions prior to v5.11. This vulnerability allows an attacker to perform denial of service attacks by providing specially crafted responses from a Git server which triggers resource exhaustion in go-git clients.
Applications using only the in-memory filesystem supported by go-git are not affected by this vulnerability. This is a go-git implementation issue and does not affect the upstream git cli.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade nfpm | Aug 22, 2024 | Jan 12, 2024 |
| Amazon Linux Ami 2 | — | Upgrade amazon-ssm-agentUpgrade amazon-ssm-agent-debuginfo | Apr 25, 2024 | Jan 12, 2024 |
| Amazon_linux | — | Upgrade amazon-ssm-agent | Apr 25, 2024 | Jan 12, 2024 |
| Amazon_linux_2023 | — | Upgrade amazon-ssm-agent-debuginfoUpgrade amazon-ssm-agent-debugsourceUpgrade amazon-ssm-agent | Feb 17, 2025 | Dec 24, 2023 |
| Debian | — | No solution existsUpgrade golang-github-go-git-go-git | May 15, 2025 | Jan 12, 2024 |
| Ubuntu | — | Upgrade go-git (Ubuntu Pro)Upgrade golang-github-go-git-go-git-dev (Ubuntu Pro) | Mar 13, 2026 | Jan 12, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub