CVE-2026-34165Integer Underflow (Wrap or Wraparound) in Go-git Go-git V5

Severity
5.0MEDIUMNVD
EPSS
0.0%
top 97.79%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 31
Latest updateApr 7

Description

go-git is an extensible git implementation library written in pure Go. From version 5.0.0 to before version 5.17.1, a vulnerability has been identified in which a maliciously crafted .idx file can cause asymmetric memory consumption, potentially exhausting available memory and resulting in a denial-of-service (DoS) condition. Exploitation requires write access to the local repository's .git directory, it order to create or alter existing .idx files. This issue has been patched in version 5.17.1.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:HExploitability: 1.3 | Impact: 3.6

Affected Packages4 packages

NVDgo-git_project/go-git5.0.05.17.1
Gogithub.com/go-git_go-git_v55.0.05.17.1
CVEListV5go-git/go-git>= 5.0.0, < 5.17.1

🔴Vulnerability Details

4
OSV
Maliciously crafted idx file can cause asymmetric memory consumption in github.com/go-git/go-git2026-04-07
OSV
CVE-2026-34165: go-git is an extensible git implementation library written in pure Go2026-03-31
GHSA
go-git: Maliciously crafted idx file can cause asymmetric memory consumption2026-03-30
OSV
go-git: Maliciously crafted idx file can cause asymmetric memory consumption2026-03-30

📋Vendor Advisories

2
Red Hat
github.com/go-git/go-git/v5: go-git: Denial of Service via crafted .idx file2026-03-31
Debian
CVE-2026-34165: golang-github-go-git-go-git - go-git is an extensible git implementation library written in pure Go. From vers...2026

🕵️Threat Intelligence

50
Wiz
CVE-2026-20883 Impact, Exploitability, and Mitigation Steps | Wiz
Wiz
CVE-2026-28375 Impact, Exploitability, and Mitigation Steps | Wiz
Wiz
CVE-2026-27137 Impact, Exploitability, and Mitigation Steps | Wiz
Wiz
CVE-2026-20800 Impact, Exploitability, and Mitigation Steps | Wiz
Wiz
CVE-2026-23992 Impact, Exploitability, and Mitigation Steps | Wiz

💬Community

2
Bugzilla
CVE-2026-34165 trivy: go-git: Denial of Service via crafted .idx file [fedora-all]2026-04-02
Bugzilla
CVE-2026-34165 vagrant: go-git: Denial of Service via crafted .idx file [fedora-all]2026-04-02