Denial-of-Service Vulnerability in go-git by The Go Programming Language
CVE-2026-34165

5MEDIUM

Key Information:

Vendor

Go-git

Status
Vendor
CVE Published:
31 March 2026

What is CVE-2026-34165?

A vulnerability in the go-git library, ranging from versions 5.0.0 to 5.17.0, allows attackers with write access to the local repository's .git directory to create or modify .idx files. This can trigger asymmetric memory consumption, leading to potential exhaustion of memory resources and causing a denial-of-service (DoS) condition. Users are advised to upgrade to version 5.17.1 or later to mitigate this risk. For further details, refer to the official security advisory and release notes.

Affected Version(s)

go-git >= 5.0.0, < 5.17.1

References

CVSS V3.1

Score:
5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.