Uncontrolled Recursion in isomorphic-git - CVE-2026-63475
Published: August 5, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to uncontrolled recursion in GitRefManager.resolve() when resolving server-supplied symbolic references written during a clone. A remote attacker can advertise circular symref capabilities to cause a denial of service.
User interaction is required to clone from a malicious or man-in-the-middle server.