Uncontrolled Memory Allocation in isomorphic-git - CVE-2026-63476
Published: August 5, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to memory allocation with excessive size value in src/utils/applyDelta.js when applying a delta object from a packfile during git clone or fetch operations. A remote attacker can send a specially crafted packfile response to cause a denial of service.
User interaction is required to initiate a clone or fetch operation against a malicious or man-in-the-middle server.