Resource exhaustion in go-git - #VU131779
Published: May 19, 2026
go-git
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to uncontrolled resource consumption in Git object parsing when processing maliciously crafted Git repository data. A remote attacker can supply crafted .pack, .idx, or loose object data to cause a denial of service.
User interaction is required, such as interacting with a malicious remote server.