Bug 2483894 (CVE-2026-44740) - CVE-2026-44740 github.com/go-git/go-billy: Billy: Denial of Service via crafted input due to insufficient validation
Summary: CVE-2026-44740 github.com/go-git/go-billy: Billy: Denial of Service via craft...
Keywords:
Status: NEW
Alias: CVE-2026-44740
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2496423 2496484 2496485 2496487 2496488 2496489 2496492 2496493 2496494 2496495 2496496 2496497 2496498 2496499 2496500 2496501 2496502 2496507 2496508 2496510 2496512 2496515 2496516 2496517 2496520 2496522 2496523 2496490 2496503 2496505 2496506 2496511 2496513 2496518
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-06-02 04:26 UTC by Sandipan Roy
Modified: 2026-07-02 13:05 UTC (History)
101 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description Sandipan Roy 2026-06-02 04:26:41 UTC
Billy is an interface filesystem abstraction for Go. Prior to versions 5.9.0 and 6.0.0-alpha.1, multiple components may improperly handle crafted or malformed input, resulting in panics, infinite loops, uncontrolled recursion, or excessive resource consumption. These issues arise from insufficient validation and missing safety mechanisms such as cycle detection, recursion limits, or defensive handling of unexpected states when processing untrusted repository data and filesystem structures. This issue has been patched in versions 5.9.0 and 6.0.0-alpha.1.


Note You need to log in before you can comment on or make changes to this bug.