go-git is a highly extensible git implementation library written in pure Go. A denial of service (DoS) vulnerability was discovered in go-git versions prior to v5.13. This vulnerability allows an attacker to perform denial of service attacks by providing specially crafted responses from a Git server which triggers resource exhaustion in go-git clients. Users running versions of go-git from v4 and above are recommended to upgrade to v5.13 in order to mitigate this vulnerability.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade grafana-selinuxUpgrade grafana | Jan 21, 2025 | Jan 6, 2025 |
| Amazon Linux Ami 2 | — | Upgrade amazon-ssm-agent | Feb 5, 2025 | Jan 6, 2025 |
| Amazon_linux_2023 | — | Upgrade amazon-ssm-agent | Feb 17, 2025 | Jan 6, 2025 |
| Debian | — | Upgrade golang-github-go-git-go-git | May 15, 2025 | Jan 6, 2025 |
| Oracle_linux | — | Upgrade grafanaUpgrade grafana-selinux | Jan 20, 2025 | Jan 6, 2025 |
| Redhat_linux | — | Upgrade grafanaUpgrade grafana-debugsourceUpgrade grafana-debuginfoNo solution existsUpgrade grafana-selinux | Jan 22, 2025 | Jan 6, 2025 |
| Rocky_linux | — | Upgrade grafana-debugsourceUpgrade grafana-debuginfoUpgrade grafanaUpgrade grafana-selinux | Feb 14, 2025 | Jan 6, 2025 |
| Suse | — | Upgrade govulncheck-vulndbUpgrade trivy | Jan 13, 2025 | Jan 6, 2025 |
| Ubuntu | — | Upgrade go-git (Ubuntu Pro)Upgrade golang-github-go-git-go-git-dev (Ubuntu Pro) | Mar 13, 2026 | Jan 6, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub