{"schema_version":"1.9.0","id":"GHSA-mw99-9chc-xw7r","published":"2023-12-27T15:06:52Z","modified":"2026-09-10T03:49:59.657751880Z","aliases":["CVE-2023-49568","GO-2024-2466"],"summary":"Maliciously crafted Git server replies can cause DoS on go-git clients","details":"### Impact\nA denial of service (DoS) vulnerability was discovered in go-git versions prior to `v5.11`. This vulnerability allows an attacker to perform denial of service attacks by providing specially crafted responses from a Git server which triggers resource exhaustion in `go-git` clients. \n\nApplications using only the in-memory filesystem supported by `go-git` are not affected by this vulnerability.\nThis is a `go-git` implementation issue and does not affect the upstream `git` cli.\n\n### Patches\nUsers running versions of `go-git` from `v4` and above are recommended to upgrade to `v5.11` in order to mitigate this vulnerability.\n\n### Workarounds\nIn cases where a bump to the latest version of `go-git` is not possible, we recommend limiting its use to only trust-worthy Git servers.\n\n## Credit\nThanks to Ionut Lalu for responsibly disclosing this vulnerability to us.\n\n### References\n- [GHSA-mw99-9chc-xw7r](https://github.com/go-git/go-git/security/advisories/GHSA-mw99-9chc-xw7r)\n","affected":[{"package":{"name":"github.com/go-git/go-git/v5","ecosystem":"Go","purl":"pkg:golang/github.com/go-git/go-git/v5"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"5.11.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/12/GHSA-mw99-9chc-xw7r/GHSA-mw99-9chc-xw7r.json"}},{"package":{"name":"gopkg.in/src-d/go-git.v4","ecosystem":"Go","purl":"pkg:golang/gopkg.in/src-d/go-git.v4"},"ranges":[{"type":"SEMVER","events":[{"introduced":"4.7.1"},{"last_affected":"4.13.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/12/GHSA-mw99-9chc-xw7r/GHSA-mw99-9chc-xw7r.json"}}],"references":[{"type":"WEB","url":"https://github.com/go-git/go-git/security/advisories/GHSA-mw99-9chc-xw7r"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-49568"},{"type":"PACKAGE","url":"https://github.com/go-git/go-git"}],"database_specific":{"cwe_ids":["CWE-20"],"github_reviewed":true,"github_reviewed_at":"2023-12-27T15:06:52Z","nvd_published_at":"2024-01-12T11:15:12Z","severity":"HIGH"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}