CVE-2025-21614
ADVISORY - githubSummary
Impact
A denial of service (DoS) vulnerability was discovered in go-git versions prior to v5.13. This vulnerability allows an attacker to perform denial of service attacks by providing specially crafted responses from a Git server which triggers resource exhaustion in go-git clients.
This is a go-git implementation issue and does not affect the upstream git cli.
Patches
Users running versions of go-git from v4 and above are recommended to upgrade to v5.13 in order to mitigate this vulnerability.
Workarounds
In cases where a bump to the latest version of go-git is not possible, we recommend limiting its use to only trust-worthy Git servers.
Credit
Thanks to Ionut Lalu for responsibly disclosing this vulnerability to us.
Common Weakness Enumeration (CWE)
Uncontrolled Resource Consumption
OWASP Top Ten 2017 Category A9 - Using Components with Known Vulnerabilities
Improper Input Validation
Uncontrolled Resource Consumption
Allocation of Resources Without Limits or Throttling
OWASP Top Ten 2013 Category A9 - Using Components with Known Vulnerabilities
NIST
3.9
CVSS SCORE
7.5highGitHub
CVSS SCORE
7.5highDebian
-
Ubuntu
-
CVSS SCORE
N/AmediumGoLang
-
Alma
-
CVSS SCORE
N/AhighAmazon
-
CVSS SCORE
N/AhighAmazon
-
CVSS SCORE
N/AhighRed Hat
3.9
CVSS SCORE
7.5highRocky
-
CVSS SCORE
N/AhighOracle
-
CVSS SCORE
N/AhighChainguard
CGA-25c9-3jr6-jxxg
-
Chainguard
CGA-2j27-9jch-r324
-
Chainguard
CGA-2qr6-pww9-rvrw
-
Chainguard
CGA-34hc-r27q-mqxj
-
Chainguard
CGA-39hj-9mfr-82c9
-
Chainguard
CGA-3h2w-crfm-c9gv
-
Chainguard
CGA-3hcf-82m4-jv8g
-
Chainguard
CGA-3qvf-p8pm-rccq
-
Chainguard
CGA-42gf-352f-h47v
-
Chainguard
CGA-46xm-6g2f-4cmx
-
Chainguard
CGA-4949-7hhp-mfwq
-
Chainguard
CGA-4mfq-qwq3-crjj
-
Chainguard
CGA-4pc6-rw7j-v45x
-
Chainguard
CGA-4r82-8h43-3c72
-
Chainguard
CGA-4vxc-2qw8-5v4q
-
Chainguard
CGA-522w-5h2g-rq48
-
Chainguard
CGA-533m-33r2-x84m
-
Chainguard
CGA-5j4g-3886-7v27
-
Chainguard
CGA-5m79-5w86-96qw
-
Chainguard
CGA-5mf4-9qx3-q7g3
-
Chainguard
CGA-5r2p-7fg5-qp35
-
Chainguard
CGA-659p-xcf5-v3f3
-
Chainguard
CGA-65x8-r639-7486
-
Chainguard
CGA-68jx-fh72-v454
-
Chainguard
CGA-6f8c-qjcw-xj4f
-
Chainguard
CGA-6w85-7vgh-xj58
-
Chainguard
CGA-6x4p-h662-pw5r
-
Chainguard
CGA-6xvp-pf79-x48j
-
Chainguard
CGA-72pf-vrm4-5rxh
-
Chainguard
CGA-74m3-h68x-x3r8
-
Chainguard
CGA-7f4h-7ph7-8w8m
-
Chainguard
CGA-7jvp-cm8h-gq29
-
Chainguard
CGA-7qpw-cgjm-7gh9
-
Chainguard
CGA-82c3-rr5r-47cr
-
Chainguard
CGA-8fcr-29p8-r7xg
-
Chainguard
CGA-8j2x-86w8-w398
-
Chainguard
CGA-8w56-f4x5-3c94
-
Chainguard
CGA-92xw-xxm9-22rg
-
Chainguard
CGA-9382-jc5c-q4gc
-
Chainguard
CGA-947j-rp4h-c6jc
-
Chainguard
CGA-9736-4825-g56m
-
Chainguard
CGA-97qf-hjxm-mjgv
-
Chainguard
CGA-9q56-86g9-6ppw
-
Chainguard
CGA-9qxg-j6r4-2rc7
-
Chainguard
CGA-c477-jx73-j2f7
-
Chainguard
CGA-c4rr-2f8q-x6xh
-
Chainguard
CGA-c53m-wj6m-g89q
-
Chainguard
CGA-cf2r-m68m-h4hq
-
Chainguard
CGA-cpr9-v5xx-mhfm
-
Chainguard
CGA-cr98-m5gm-57q7
-
Chainguard
CGA-fgr7-pwc3-2367
-
Chainguard
CGA-fqjp-gqgv-chrp
-
Chainguard
CGA-fwcg-h4x9-8xr4
-
Chainguard
CGA-fxxc-w9cp-gg3w
-
Chainguard
CGA-g3jj-gxhm-g5jj
-
Chainguard
CGA-gc77-5phf-vxm8
-
Chainguard
CGA-grc2-44h2-w25p
-
Chainguard
CGA-gvfg-pq6f-2fwq
-
Chainguard
CGA-h665-8mm8-2hq6
-
Chainguard
CGA-hf64-r9ph-3737
-
Chainguard
CGA-hmhh-pcv9-5925
-
Chainguard
CGA-j2rp-fqh7-643g
-
Chainguard
CGA-jfjj-c8f2-8jwg
-
Chainguard
CGA-jj5h-hmwf-mmmr
-
Chainguard
CGA-jpj5-hj9h-2659
-
Chainguard
CGA-m53m-7mr9-m2wp
-
Chainguard
CGA-m689-4c3w-4qx5
-
Chainguard
CGA-mcqm-r723-8xpm
-
Chainguard
CGA-mhgh-fvh8-hvj7
-
Chainguard
CGA-mmrm-qfr7-g2w5
-
Chainguard
CGA-mq8r-c5gf-jvxw
-
Chainguard
CGA-mqpq-qrj4-2hj9
-
Chainguard
CGA-mr43-vw9h-c5jx
-
Chainguard
CGA-mv62-q8c4-pqh7
-
Chainguard
CGA-mv9j-547c-r67m
-
Chainguard
CGA-mvwv-q6jx-8jvr
-
Chainguard
CGA-p74p-5f53-p34c
-
Chainguard
CGA-p88v-hqxj-6wr9
-
Chainguard
CGA-p9fx-rmq6-fhgj
-
Chainguard
CGA-pc74-h874-vf2j
-
Chainguard
CGA-pcc5-v84x-9cvx
-
Chainguard
CGA-pjf8-phcp-8c4r
-
Chainguard
CGA-pmgf-xv5j-f3qr
-
Chainguard
CGA-q54x-24m2-vj2f
-
Chainguard
CGA-qfxp-35rx-vp74
-
Chainguard
CGA-qmg4-fj2g-77px
-
Chainguard
CGA-qmpc-49qf-33h6
-
Chainguard
CGA-qq84-g98h-8957
-
Chainguard
CGA-r49j-xm48-4f37
-
Chainguard
CGA-r4p7-5659-wj66
-
Chainguard
CGA-r69w-p3xr-4vpw
-
Chainguard
CGA-rc9p-f629-6pr4
-
Chainguard
CGA-rcxw-hfwp-q4cx
-
Chainguard
CGA-rjjg-xxq6-9m54
-
Chainguard
CGA-rqrp-5g3v-mv2p
-
Chainguard
CGA-rxrq-jmmh-wchr
-
Chainguard
CGA-v8x4-7hq3-9jp4
-
Chainguard
CGA-vcfc-jvvw-jjhm
-
Chainguard
CGA-vp8v-c6r9-6vxr
-
Chainguard
CGA-vp95-64w7-72v5
-
Chainguard
CGA-vpqw-7vr4-49wr
-
Chainguard
CGA-vqmw-p6p7-qpqw
-
Chainguard
CGA-vrwf-vm3x-frp4
-
Chainguard
CGA-vvmc-7mgm-gcvc
-
Chainguard
CGA-w2cm-68ww-m362
-
Chainguard
CGA-w7r5-x3rp-f7g3
-
Chainguard
CGA-w7w5-364f-67p2
-
Chainguard
CGA-wccq-9g8j-w469
-
Chainguard
CGA-wv9c-q6j7-75mv
-
Chainguard
CGA-x982-x58x-37xq
-
Chainguard
CGA-xc7v-j9xf-9c5h
-
minimos
MINI-74vx-8m8w-2c93
-
minimos
MINI-8x5v-rr3g-mgvw
-