Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-44740

Опубликовано: 01 июн. 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

Billy is an interface filesystem abstraction for Go. Prior to versions 5.9.0 and 6.0.0-alpha.1, multiple components may improperly handle crafted or malformed input, resulting in panics, infinite loops, uncontrolled recursion, or excessive resource consumption. These issues arise from insufficient validation and missing safety mechanisms such as cycle detection, recursion limits, or defensive handling of unexpected states when processing untrusted repository data and filesystem structures. This issue has been patched in versions 5.9.0 and 6.0.0-alpha.1.

A flaw was found in Billy, an interface filesystem abstraction for Go. This vulnerability allows a remote attacker to cause a Denial of Service (DoS) by providing crafted or malformed input. The issue arises from insufficient validation and missing safety mechanisms when processing untrusted repository data and filesystem structures, leading to panics, infinite loops, uncontrolled recursion, or excessive resource consumption.

Отчет

This is rated as an Important severity issue. The go-billy library, a Go filesystem abstraction, is vulnerable to a denial of service when processing crafted or malformed input, such as untrusted repository data or filesystem structures. Insufficient validation and missing safety mechanisms can lead to panics, infinite loops, or excessive resource consumption, potentially impacting the availability of applications that rely on this library.

Меры по смягчению последствий

To mitigate the issue, we suggest upgrading to versions 5.9.0+ or 6.0.0-alpha.1+

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Assisted Installer for Red Hat OpenShift Container Platform 2assisted/agent-preinstall-image-builder-rhel9Affected
Builds for Red Hat OpenShiftopenshift-builds/openshift-builds-controller-rhel9Affected
Builds for Red Hat OpenShiftopenshift-builds/openshift-builds-git-cloner-rhel9Affected
Builds for Red Hat OpenShiftopenshift-builds/openshift-builds-image-bundler-rhel9Affected
Builds for Red Hat OpenShiftopenshift-builds/openshift-builds-image-processing-rhel9Affected
Builds for Red Hat OpenShiftopenshift-builds/openshift-builds-waiters-rhel9Affected
Builds for Red Hat OpenShiftopenshift-builds/openshift-builds-webhook-rhel9Affected
Confidential Compute Attestationopenshift-sandboxed-containers/osc-must-gather-rhel9Affected
Exploit Intelligenceexploit-intelligence-tech-preview/agent-client-rhel9Affected
Exploit Intelligenceexploit-intelligence-tech-preview/vulnerability-analysis-rhel9Affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-606
https://bugzilla.redhat.com/show_bug.cgi?id=2483894github.com/go-git/go-billy: Billy: Denial of Service via crafted input due to insufficient validation

EPSS

Процентиль: 22%
0.00295
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
около 2 месяцев назад

Billy is an interface filesystem abstraction for Go. Prior to versions 5.9.0 and 6.0.0-alpha.1, multiple components may improperly handle crafted or malformed input, resulting in panics, infinite loops, uncontrolled recursion, or excessive resource consumption. These issues arise from insufficient validation and missing safety mechanisms such as cycle detection, recursion limits, or defensive handling of unexpected states when processing untrusted repository data and filesystem structures. This issue has been patched in versions 5.9.0 and 6.0.0-alpha.1.

CVSS3: 6.5
nvd
около 2 месяцев назад

Billy is an interface filesystem abstraction for Go. Prior to versions 5.9.0 and 6.0.0-alpha.1, multiple components may improperly handle crafted or malformed input, resulting in panics, infinite loops, uncontrolled recursion, or excessive resource consumption. These issues arise from insufficient validation and missing safety mechanisms such as cycle detection, recursion limits, or defensive handling of unexpected states when processing untrusted repository data and filesystem structures. This issue has been patched in versions 5.9.0 and 6.0.0-alpha.1.

CVSS3: 6.5
debian
около 2 месяцев назад

Billy is an interface filesystem abstraction for Go. Prior to versions ...

CVSS3: 6.5
github
3 месяца назад

go-billy: Lack of depth and cycle detection in symlink resolution may lead to infinite loops and resource exhaustion

suse-cvrf
около 1 месяца назад

Security update for trivy

EPSS

Процентиль: 22%
0.00295
Низкий

7.5 High

CVSS3