fix: Allocation of Resources Without Limits or Throttling in github.com/go-git/go-git/v5/plumbing [IDE-855] #746
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Description
github.com/go-git/go-git/v5/plumbing is a highly extensible git implementation library written in pure Go.
Affected versions of this package are vulnerable to Allocation of Resources Without Limits or Throttling via specially crafted responses from a Git server, which triggers resource exhaustion in clients.
More about this issue
Vulnerability in github.com/snyk/snyk-ls:go.mod
Introduced through: github.com/go-git/go-git/v5, github.com/go-git/go-git/v5/config, github.com/go-git/go-git/v5/plumbing, github.com/go-git/go-git/v5/storage/filesystem, github.com/snyk/code-client-go, github.com/snyk/code-client-go/scan, github.com/snyk/go-application-framework/pkg/app, github.com/snyk/go-application-framework/pkg/instrumentation, github.com/snyk/go-application-framework/pkg/local_workflows
CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS Score: 8.7
Checklist