Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-44740

Опубликовано: 01 июн. 2026
Источник: debian
EPSS Низкий

Описание

Billy is an interface filesystem abstraction for Go. Prior to versions 5.9.0 and 6.0.0-alpha.1, multiple components may improperly handle crafted or malformed input, resulting in panics, infinite loops, uncontrolled recursion, or excessive resource consumption. These issues arise from insufficient validation and missing safety mechanisms such as cycle detection, recursion limits, or defensive handling of unexpected states when processing untrusted repository data and filesystem structures. This issue has been patched in versions 5.9.0 and 6.0.0-alpha.1.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
golang-github-go-git-go-billyfixed5.9.0-1package
golang-github-go-git-go-billyno-dsatrixiepackage
golang-github-go-git-go-billypostponedbookwormpackage
golang-github-go-git-go-billy-v6fixed6.0.0~alpha.1-1package

Примечания

  • https://github.com/go-git/go-billy/security/advisories/GHSA-m3xc-h892-ggx6

EPSS

Процентиль: 22%
0.00295
Низкий

Связанные уязвимости

CVSS3: 6.5
ubuntu
около 2 месяцев назад

Billy is an interface filesystem abstraction for Go. Prior to versions 5.9.0 and 6.0.0-alpha.1, multiple components may improperly handle crafted or malformed input, resulting in panics, infinite loops, uncontrolled recursion, or excessive resource consumption. These issues arise from insufficient validation and missing safety mechanisms such as cycle detection, recursion limits, or defensive handling of unexpected states when processing untrusted repository data and filesystem structures. This issue has been patched in versions 5.9.0 and 6.0.0-alpha.1.

CVSS3: 7.5
redhat
около 2 месяцев назад

Billy is an interface filesystem abstraction for Go. Prior to versions 5.9.0 and 6.0.0-alpha.1, multiple components may improperly handle crafted or malformed input, resulting in panics, infinite loops, uncontrolled recursion, or excessive resource consumption. These issues arise from insufficient validation and missing safety mechanisms such as cycle detection, recursion limits, or defensive handling of unexpected states when processing untrusted repository data and filesystem structures. This issue has been patched in versions 5.9.0 and 6.0.0-alpha.1.

CVSS3: 6.5
nvd
около 2 месяцев назад

Billy is an interface filesystem abstraction for Go. Prior to versions 5.9.0 and 6.0.0-alpha.1, multiple components may improperly handle crafted or malformed input, resulting in panics, infinite loops, uncontrolled recursion, or excessive resource consumption. These issues arise from insufficient validation and missing safety mechanisms such as cycle detection, recursion limits, or defensive handling of unexpected states when processing untrusted repository data and filesystem structures. This issue has been patched in versions 5.9.0 and 6.0.0-alpha.1.

rocky
3 дня назад

Important: grafana security, bug fix, and enhancement update

CVSS3: 6.5
github
3 месяца назад

go-billy: Lack of depth and cycle detection in symlink resolution may lead to infinite loops and resource exhaustion

EPSS

Процентиль: 22%
0.00295
Низкий