go-git is a highly extensible git implementation library written in pure Go. A denial of service (DoS) vulnerability was discovered in go-git versions prior to v5.13. This vulnerability allows an attacker to perform denial of service attacks by providing specially crafted responses from a Git server which triggers resource exhaustion in go-git clients. Users running versions of go-git from v4 and above are recommended to upgrade to v5.13 in order to mitigate this vulnerability.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade grafana-selinuxUpgrade grafana | Jan 21, 2025 | Jan 6, 2025 |
| Amazon Linux Ami 2 | — | Upgrade amazon-ssm-agent | Feb 5, 2025 | Jan 6, 2025 |
| Amazon_linux_2023 | — | Upgrade amazon-ssm-agent | Feb 17, 2025 | Jan 6, 2025 |
| Debian | — | Upgrade golang-github-go-git-go-gitNo solution exists | May 15, 2025 | Jan 6, 2025 |
| Oracle_linux | — | Upgrade grafanaUpgrade grafana-selinux | Jan 20, 2025 | Jan 6, 2025 |
| Redhat_linux | — | Upgrade grafana-selinuxUpgrade grafana-debuginfoNo solution existsUpgrade grafanaUpgrade grafana-debugsource | Jan 22, 2025 | Jan 6, 2025 |
| Rocky_linux | — | Upgrade grafana-selinuxUpgrade grafanaUpgrade grafana-debugsourceUpgrade grafana-debuginfo | Feb 14, 2025 | Jan 6, 2025 |
| Suse | — | Upgrade govulncheck-vulndbUpgrade trivy | Jan 13, 2025 | Jan 6, 2025 |
| Ubuntu | — | Upgrade golang-github-go-git-go-git-dev (Ubuntu Pro)Upgrade go-git (Ubuntu Pro) | Mar 13, 2026 | Jan 6, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub