PT-2026-29159 · Go-Git+1 · Go-Git+1

·

CVE-2026-34165

·

Publicado

2026-03-29

·

Atualizado

2026-07-30

CVSS v3.1

5.0

Média

VetorAV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions go-git versions 5.0.0 through 5.17.0
Description A crafted .idx file can cause asymmetric memory consumption, potentially exhausting available memory and resulting in a denial-of-service (DoS) condition. Exploitation requires write access to the local repository's .git directory to create or alter existing .idx files.
Recommendations Upgrade to version 5.17.1 or later.

Exploit

Correção

DoS

Integer Underflow

Allocation of Resources Without Limits

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2026-11028
CLEANSTART-2026-BU65096
CLEANSTART-2026-DQ17669
CLEANSTART-2026-EH36582
CLEANSTART-2026-ET12387
CLEANSTART-2026-FV86809
CLEANSTART-2026-GN78570
CLEANSTART-2026-HO16255
CLEANSTART-2026-JG72006
CLEANSTART-2026-KL41807
CLEANSTART-2026-KO23583
CLEANSTART-2026-LO26058
CLEANSTART-2026-LU21824
CLEANSTART-2026-ML41879
CLEANSTART-2026-NR54556
CLEANSTART-2026-NT80635
CLEANSTART-2026-PD78752
CLEANSTART-2026-QT53274
CLEANSTART-2026-TT42218
CLEANSTART-2026-VT65447
CLEANSTART-2026-WF25734
CLEANSTART-2026-YZ90223
CVE-2026-34165
GHSA-JHF3-XXHW-2WPP
GO-2026-4910
OPENSUSE-SU-2026:10509-1
OPENSUSE-SU-2026:10684-1
OPENSUSE-SU-2026:21483-1

Produtos afetados

Red Os
Go-Git