CVE-2025-21614: go-git clients vulnerable to DoS via maliciously crafted Git server replies
A denial of service (DoS) vulnerability was discovered in go-git versions prior to v5.13
. This vulnerability allows an attacker to perform denial of service attacks by providing specially crafted responses from a Git server which triggers resource exhaustion in go-git
clients.
This is a go-git
implementation issue and does not affect the upstream git
cli.
References
Detect and mitigate CVE-2025-21614 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →