{"schema_version":"1.7.3","id":"GHSA-r9px-m959-cxf4","published":"2025-01-06T16:20:28Z","modified":"2026-02-04T02:33:46.739962Z","aliases":["CVE-2025-21614","GO-2025-3367"],"related":["CGA-rxrq-jmmh-wchr"],"summary":"go-git clients vulnerable to DoS via maliciously crafted Git server replies","details":"### Impact\nA denial of service (DoS) vulnerability was discovered in go-git versions prior to `v5.13`. This vulnerability allows an attacker to perform denial of service attacks by providing specially crafted responses from a Git server which triggers resource exhaustion in `go-git` clients. \n\nThis is a `go-git` implementation issue and does not affect the upstream `git` cli.\n\n### Patches\nUsers running versions of `go-git` from `v4` and above are recommended to upgrade to `v5.13` in order to mitigate this vulnerability.\n\n### Workarounds\nIn cases where a bump to the latest version of `go-git` is not possible, we recommend limiting its use to only trust-worthy Git servers.\n\n## Credit\nThanks to Ionut Lalu for responsibly disclosing this vulnerability to us.","affected":[{"package":{"name":"gopkg.in/src-d/go-git.v4","ecosystem":"Go","purl":"pkg:golang/gopkg.in/src-d/go-git.v4"},"ranges":[{"type":"SEMVER","events":[{"introduced":"4.0.0"},{"last_affected":"4.13.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/01/GHSA-r9px-m959-cxf4/GHSA-r9px-m959-cxf4.json"}},{"package":{"name":"github.com/go-git/go-git/v5","ecosystem":"Go","purl":"pkg:golang/github.com/go-git/go-git/v5"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"5.13.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/01/GHSA-r9px-m959-cxf4/GHSA-r9px-m959-cxf4.json"}},{"package":{"name":"github.com/go-git/go-git","ecosystem":"Go","purl":"pkg:golang/github.com/go-git/go-git"},"ranges":[{"type":"SEMVER","events":[{"introduced":"4.0.0"},{"last_affected":"4.13.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/01/GHSA-r9px-m959-cxf4/GHSA-r9px-m959-cxf4.json"}}],"references":[{"type":"WEB","url":"https://github.com/go-git/go-git/security/advisories/GHSA-r9px-m959-cxf4"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-21614"},{"type":"PACKAGE","url":"https://github.com/go-git/go-git"}],"database_specific":{"cwe_ids":["CWE-20","CWE-400","CWE-770"],"github_reviewed":true,"github_reviewed_at":"2025-01-06T16:20:28Z","nvd_published_at":"2025-01-06T17:15:47Z","severity":"HIGH"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}