<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 01:31:13 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-5956</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-5956</link>
      <description>EUVD-2026-5956</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-5956</guid>
    </item>
    <item>
      <title>fkie_cve-2024-37904</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-37904</link>
      <description>&lt;p&gt;Minder is an open source Software Supply Chain Security Platform. Minder&amp;#39;s Git provider is vulnerable to a denial of service from a maliciously configured GitHub repository. The Git provider clones users repositories using the `github.com/go-git/go-git/v5` library on lines `L55-L89`. The Git provider does the following on the lines `L56-L62`. First, it sets the `CloneOptions`, specifying the url, the depth etc. It then validates the options. It then sets up an in-memory filesystem, to which it clones and Finally, it clones the repository. The `(g *Git) Clone()` method is vulnerable to a DoS attack: A Minder user can instruct Minder to clone a large repository which will exhaust memory and crash the Minder server. The root cause of this vulnerability is a combination of the following conditions: 1. Users can control the Git URL which Minder clones, 2. Minder does not enforce a size limit to the repository, 3. Minder clones the entire repository into memory. This issue has been addressed in commit `7979b43` which has been included in release version v0.0.52. Users are advised to upgrade. There are no known workarounds for this vulnerability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Minder is an open source Software Supply Chain Security Platform. Minder&amp;#39;s Git provider is vulnerable to a denial of service from a maliciously configured GitHub repository. The Git provider clones users repositories using the `github.com/go-git/go-git/v5` library on lines `L55-L89`. The Git provider does the following on the lines `L56-L62`. First, it sets the `CloneOptions`, specifying the url, the depth etc. It then validates the options. It then sets up an in-memory filesystem, to which it clones and Finally, it clones the repository. The `(g *Git) Clone()` method is vulnerable to a DoS attack: A Minder user can instruct Minder to clone a large repository which will exhaust memory and crash the Minder server. The root cause of this vulnerability is a combination of the following conditions: 1. Users can control the Git URL which Minder clones, 2. Minder does not enforce a size limit to the repository, 3. Minder clones the entire repository into memory. This issue has been addressed in commit `7979b43` which has been included in release version v0.0.52. Users are advised to upgrade. There are no known workarounds for this vulnerability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-37904</guid>
    </item>
    <item>
      <title>GHSA-hpcg-xjq5-g666 — Minder affected by denial of service from maliciously configured Git repository</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-hpcg-xjq5-g666</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/stacklok/minder&lt;/p&gt;
&lt;p&gt;Minder&amp;#39;s Git provider is vulnerable to a denial of service from a maliciously configured GitHub repository. The Git provider clones users repositories using the `github.com/go-git/go-git/v5` library on these lines:&lt;/p&gt;
&lt;p&gt;https://github.com/stacklok/minder/blob/85985445c8ac3e51f03372e99c7b2f08a6d274aa/internal/providers/git/git.go#L55-L89&lt;/p&gt;
&lt;p&gt;The Git provider does the following on these lines:&lt;/p&gt;
&lt;p&gt;First, it sets the `CloneOptions`, specifying the url, the depth etc:&lt;/p&gt;
&lt;p&gt;https://github.com/stacklok/minder/blob/85985445c8ac3e51f03372e99c7b2f08a6d274aa/internal/providers/git/git.go#L56-L62&lt;/p&gt;
&lt;p&gt;It then validates the options:&lt;/p&gt;
&lt;p&gt;https://github.com/stacklok/minder/blob/85985445c8ac3e51f03372e99c7b2f08a6d274aa/internal/providers/git/git.go#L66-L68&lt;/p&gt;
&lt;p&gt;It then sets up an in-memory filesystem, to which it clones:&lt;/p&gt;
&lt;p&gt;https://github.com/stacklok/minder/blob/85985445c8ac3e51f03372e99c7b2f08a6d274aa/internal/providers/git/git.go#L70-L71&lt;/p&gt;
&lt;p&gt;Finally, it clones the repository:&lt;/p&gt;
&lt;p&gt;https://github.com/stacklok/minder/blob/85985445c8ac3e51f03372e99c7b2f08a6d274aa/internal/providers/git/git.go#L77&lt;/p&gt;
&lt;p&gt;This `(g *Git) Clone()` method is vulnerable to a DoS attack: A Minder user can instruct Minder to clone a large repository which will exhaust memory and crash the Minder server. The root cause of this vulnerability is a combination of the following conditions:&lt;/p&gt;
&lt;p&gt;1. Users can control the Git URL which Minder clones.
2. Minder does not enforce a size limit to the repository.
3. Minder clones the entire repository into memory.&lt;/p&gt;
&lt;p&gt;##…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/stacklok/minder&lt;/p&gt;
&lt;p&gt;Minder&amp;#39;s Git provider is vulnerable to a denial of service from a maliciously configured GitHub repository. The Git provider clones users repositories using the `github.com/go-git/go-git/v5` library on these lines:&lt;/p&gt;
&lt;p&gt;https://github.com/stacklok/minder/blob/85985445c8ac3e51f03372e99c7b2f08a6d274aa/internal/providers/git/git.go#L55-L89&lt;/p&gt;
&lt;p&gt;The Git provider does the following on these lines:&lt;/p&gt;
&lt;p&gt;First, it sets the `CloneOptions`, specifying the url, the depth etc:&lt;/p&gt;
&lt;p&gt;https://github.com/stacklok/minder/blob/85985445c8ac3e51f03372e99c7b2f08a6d274aa/internal/providers/git/git.go#L56-L62&lt;/p&gt;
&lt;p&gt;It then validates the options:&lt;/p&gt;
&lt;p&gt;https://github.com/stacklok/minder/blob/85985445c8ac3e51f03372e99c7b2f08a6d274aa/internal/providers/git/git.go#L66-L68&lt;/p&gt;
&lt;p&gt;It then sets up an in-memory filesystem, to which it clones:&lt;/p&gt;
&lt;p&gt;https://github.com/stacklok/minder/blob/85985445c8ac3e51f03372e99c7b2f08a6d274aa/internal/providers/git/git.go#L70-L71&lt;/p&gt;
&lt;p&gt;Finally, it clones the repository:&lt;/p&gt;
&lt;p&gt;https://github.com/stacklok/minder/blob/85985445c8ac3e51f03372e99c7b2f08a6d274aa/internal/providers/git/git.go#L77&lt;/p&gt;
&lt;p&gt;This `(g *Git) Clone()` method is vulnerable to a DoS attack: A Minder user can instruct Minder to clone a large repository which will exhaust memory and crash the Minder server. The root cause of this vulnerability is a combination of the following conditions:&lt;/p&gt;
&lt;p&gt;1. Users can control the Git URL which Minder clones.
2. Minder does not enforce a size limit to the repository.
3. Minder clones the entire repository into memory.&lt;/p&gt;
&lt;p&gt;##…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-hpcg-xjq5-g666</guid>
    </item>
  </channel>
</rss>
