{"schema_version":"1.9.0","id":"CVE-2023-49568","published":"2024-01-12T10:36:12.727Z","modified":"2026-08-12T03:51:31.633386015Z","aliases":["GHSA-mw99-9chc-xw7r","GO-2024-2466"],"related":["CGA-wwh6-vmmm-85jv"],"summary":"Maliciously crafted Git server replies can cause DoS on go-git clients","details":"A denial of service (DoS) vulnerability was discovered in go-git versions prior to v5.11. This vulnerability allows an attacker to perform denial of service attacks by providing specially crafted responses from a Git server which triggers resource exhaustion in go-git clients.\n\nApplications using only the in-memory filesystem supported by go-git are not affected by this vulnerability.\nThis is a go-git implementation issue and does not affect the upstream git cli.\n\n\n","affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/go-git/go-git","events":[{"introduced":"5d08d3bd94c65a3b6c25c6fba6907d12b0dac4ca"},{"fixed":"5d08d3bd94c65a3b6c25c6fba6907d12b0dac4ca"}],"database_specific":{"cpe":"cpe:2.3:a:go-git_project:go-git:*:*:*:*:*:go:*:*","extracted_events":[{"introduced":"5.11.0"},{"last_affected":"5.11.0"},{"introduced":"4.0.0"},{"fixed":"5.11.0"}],"source":["AFFECTED_FIELD","CPE_RANGE"]}}],"versions":["5.11.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-49568.json"}}],"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/49xxx/CVE-2023-49568.json"},{"type":"ADVISORY","url":"https://github.com/go-git/go-git/security/advisories/GHSA-mw99-9chc-xw7r"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-49568"}],"database_specific":{"cna_assigner":"Bitdefender","cwe_ids":["CWE-20"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/49xxx/CVE-2023-49568.json"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}