isomorphic-git is vulnerable to Denial of Service (DoS)
43
Medium Risk
GitRefManager.resolve() in isomorphic-git follows symbolic references with no default depth limit and no cycle detection. A malicious server can advertise circular symref capabilities that are persisted to disk as loose symrefs during clone, so any later operation that resolves them, such as log, status, checkout, or branch, loops forever. Because the bad refs are written to disk, the repository becomes permanently unusable for the application. The fix adds cycle detection so symref resolution terminates on a reference cycle.
You are affected if you are using a version that falls within the vulnerable range and you clone or fetch from untrusted or compromised remotes.
isomorphic-git is vulnerable to Denial of Service (DoS) in versions 0.0.1 - 1.38.5.
Upgrade the isomorphic-git library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant