go-git
cpe:2.3:a:go-git_project:go-git:*:*:*:*:go:*:*
- < 5.13.0
- >= 4.0.0
A denial-of-service vulnerability has been identified in go-git versions prior to 5.13. This issue allows an attacker to cause resource exhaustion in go-git clients by sending specially crafted responses from a Git server. This vulnerability does not affect the upstream Git command-line interface.
Exploitation of this vulnerability leads to a denial-of-service condition, causing high availability impact on affected systems.
Users of go-git version 4.0.0 prior to 5.13.0 should upgrade to version 5.13.0. If an immediate upgrade is not possible, it is recommended to limit the use of go-git to trusted Git servers.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.