go-git is an extensible git implementation library written in pure Go. From version 5.0.0 to before version 5.17.1, a vulnerability has been identified in which a maliciously crafted .idx file can cause asymmetric memory consumption, potentially exhausting available memory and resulting in a denial-of-service (DoS) condition. Exploitation requires write access to the local repository's .git directory, it order to create or alter existing .idx files. This issue has been patched in version 5.17.1.
References
| Link | Resource |
|---|---|
| https://github.com/go-git/go-git/releases/tag/v5.17.1 | Product Release Notes |
| https://github.com/go-git/go-git/security/advisories/GHSA-jhf3-xxhw-2wpp | Vendor Advisory |
Configurations
History
02 Apr 2026, 16:49
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:go-git_project:go-git:*:*:*:*:*:go:*:* | |
| References | () https://github.com/go-git/go-git/releases/tag/v5.17.1 - Product, Release Notes | |
| References | () https://github.com/go-git/go-git/security/advisories/GHSA-jhf3-xxhw-2wpp - Vendor Advisory | |
| First Time |
Go-git Project
Go-git Project go-git |
31 Mar 2026, 15:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-03-31 15:16
Updated : 2026-04-02 16:49
NVD link : CVE-2026-34165
Mitre link : CVE-2026-34165
CVE.ORG link : CVE-2026-34165
JSON object : View
Products Affected
go-git_project
- go-git
