github.com/go-git/go-git
cpe:2.3:a:go-git_project:go-git:*:*:*:*:go:*:*
- >= 5.0.0, <= 5.17.0
A denial-of-service vulnerability has been identified in the go-git library, specifically in versions 5.0.0 prior to 5.17.1. The issue arises from the handling of .idx files, where a maliciously crafted file can cause asymmetric memory consumption. This exploitation can lead to exhaustion of available memory, creating a DoS condition. To exploit this vulnerability, write access to the local repository's .git directory is required to create or modify .idx files.
Exploitation of this vulnerability can cause significant memory exhaustion, leading to a denial-of-service condition where the application or service becomes unresponsive or unavailable.
Users are advised to upgrade to version 5.17.1 or the latest v6 pseudo-version to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.