PT-2026-40715 · Go-Billy+1 · Go-Billy+1

·

CVE-2026-44740

·

Published

2026-05-13

·

Updated

2026-08-10

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions go-billy versions prior to v5
Description Multiple components improperly handle crafted or malformed input, which can lead to panics, infinite loops, uncontrolled recursion, or excessive resource consumption. These issues result from insufficient validation and a lack of safety mechanisms, such as cycle detection, recursion limits, or defensive handling of unexpected states, when processing untrusted repository data and filesystem structures.
Recommendations Upgrade to a supported go-billy version v5 or later.

Exploit

Fix

Infinite Loop

Uncontrolled Recursion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:46391
CLEANSTART-2026-AQ65185
CLEANSTART-2026-BG69533
CLEANSTART-2026-BP02821
CLEANSTART-2026-CP15003
CLEANSTART-2026-DM19620
CLEANSTART-2026-EH36582
CLEANSTART-2026-ES72297
CLEANSTART-2026-HO16255
CLEANSTART-2026-JW97006
CLEANSTART-2026-KL41807
CLEANSTART-2026-KQ90880
CLEANSTART-2026-MY68881
CLEANSTART-2026-OS93204
CLEANSTART-2026-QP84300
CLEANSTART-2026-QT53274
CLEANSTART-2026-UY49411
CLEANSTART-2026-VD47610
CLEANSTART-2026-WF25734
CLEANSTART-2026-WY21381
CLEANSTART-2026-YF30779
CVE-2026-44740
GHSA-M3XC-H892-GGX6
GO-2026-5490
OPENSUSE-SU-2026:10856-1
OPENSUSE-SU-2026:10941-1
OPENSUSE-SU-2026:10943-1
OPENSUSE-SU-2026:10967-1
OPENSUSE-SU-2026:10996-1
OPENSUSE-SU-2026:11053-1
OPENSUSE-SU-2026:20956-1
OPENSUSE-SU-2026:21072-1
OPENSUSE-SU-2026:21079-1
OPENSUSE-SU-2026:21251-1
OPENSUSE-SU-2026:21436-1
OPENSUSE-SU-2026:21551-1
RHSA-2026:32963
RHSA-2026:32974
RHSA-2026:35111
RHSA-2026:46391
SUSE-SU-2026:22157-1
SUSE-SU-2026:22575-1
SUSE-SU-2026:23216-1
SUSE-SU-2026:23227-1
SUSE-SU-2026:2467-1
SUSE-SU-2026:2468-1
SUSE-SU-2026:2824-1
SUSE-SU-2026:3056-1

Affected Products

Rocky Linux
Go-Billy