StackRadar

CVE-2023-49568

High

Advisory

Published 27 Dec 2023In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.007
51st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
82
of 17,781 indexed, latest versions
Container images
74
deployed by those charts
Fix available
1 of 2
affected packages

Maliciously crafted Git server replies can cause DoS on go-git clients

Carried by container images the latest versions of 82 of 17,781 indexed charts deploy, on 74 images.

Affected packageAffected versionsFixed inImages
github.com/go-git/go-git/v5golangv5.0.0, v5.1.0, v5.2.0, v5.3.0+7 more5.11.061
gopkg.in/src-d/go-git.v4golangv4.10.0, v4.13.1no fix listed16
OSV records
GHSA-mw99-9chc-xw7r
Also known as
GO-2024-2466

Charts affected

82 by stars
ChartLatestAffected imagesRadar Score
u4a-componentkubebb0.2.101 of 8See more

u4a-component kubebb 0.2.10

1 of the 8 container images this version deploys carry CVE-2023-49568.

Container imageDigestPackageFixed in
kubebb/oidc-server:v0.2.02b5894ef1e2f
github.com/go-git/go-git/v5@v5.4.2
5.11.0

Open the chart page →

13,819
grafanakubeblocksVerified publisher6.59.41 of 1See more

grafana kubeblocks 6.59.4

1 of the 1 container images this version deploys carry CVE-2023-49568.

Container imageDigestPackageFixed in
grafana/grafana:10.1.11b9ca4bbc4a2
github.com/go-git/go-git/v5@v5.4.2
5.11.0

Open the chart page →

3,561
kubeclaritykubeclarity2.23.31 of 5See more

kubeclarity kubeclarity 2.23.3

1 of the 5 container images this version deploys carry CVE-2023-49568.

Container imageDigestPackageFixed in
ghcr.io/openclarity/grype-server:v0.6.079412399f301
github.com/go-git/go-git/v5@v5.8.1
5.11.0

Open the chart page →

5,496
harborkubesphereVerified publisher1.9.31 of 11See more

harbor kubesphere 1.9.3

1 of the 11 container images this version deploys carry CVE-2023-49568.

Container imageDigestPackageFixed in
goharbor/trivy-adapter-photon:v2.5.3b9522c3f5056
github.com/go-git/go-git/v5@v5.4.2
5.11.0

Open the chart page →

17,798
deepflowkubesphere-stable6.2.6061 of 8See more

deepflow kubesphere-stable 6.2.606

1 of the 8 container images this version deploys carry CVE-2023-49568.

Container imageDigestPackageFixed in
grafana/grafana:9.5.239c849cebccc
github.com/go-git/go-git/v5@v5.4.2
5.11.0

Open the chart page →

18,316
trivy-serverlemontechVerified publisher0.1.01 of 1See more

trivy-server lemontech 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-49568.

Container imageDigestPackageFixed in
aquasec/trivy:0.32.0973d0df16189
github.com/go-git/go-git/v5@v5.4.2
5.11.0

Open the chart page →

4,271
devspace-cloudloftVerified publisher0.3.31 of 8See more

devspace-cloud loft 0.3.3

1 of the 8 container images this version deploys carry CVE-2023-49568.

Container imageDigestPackageFixed in
devspacecloud/manager:0.3.349c397413f7b
gopkg.in/src-d/go-git.v4@v4.13.1
no fix listed

Open the chart page →

9,880
kubeaddons-catalogmesosphere0.1.161 of 2See more

kubeaddons-catalog mesosphere 0.1.16

1 of the 2 container images this version deploys carry CVE-2023-49568.

Container imageDigestPackageFixed in
mesosphere/kubeaddons-catalog:v0.11.4073db43d0b8b
github.com/go-git/go-git/v5@v5.1.0
5.11.0

Open the chart page →

12,010
dexmesosphere-stable2.14.11 of 5See more

dex mesosphere-stable 2.14.1

1 of the 5 container images this version deploys carry CVE-2023-49568.

Container imageDigestPackageFixed in
mesosphere/dex:v2.37.0-d2iq.1b093d78a21ed
github.com/go-git/go-git/v5@v5.4.2
5.11.0

Open the chart page →

19,214
kommandermesosphere-stable0.39.22 of 29See more

kommander mesosphere-stable 0.39.2

2 of the 29 container images this version deploys carry CVE-2023-49568.

Container imageDigestPackageFixed in
mesosphere/kommander-federation-utility-apiserver:v0.21.2f9b769c65e24
github.com/go-git/go-git/v5@v5.2.0
gopkg.in/src-d/go-git.v4@v4.13.1
5.11.0
no fix listed
mesosphere/kubeaddons-catalog:v0.11.4073db43d0b8b
github.com/go-git/go-git/v5@v5.1.0
5.11.0

Open the chart page →

68,284
giteanovum-rgi-charts2.1.31 of 3See more

gitea novum-rgi-charts 2.1.3

1 of the 3 container images this version deploys carry CVE-2023-49568.

Container imageDigestPackageFixed in
gitea/gitea:1.13.0d5ab14cd29af
github.com/go-git/go-git/v5@v5.1.0
5.11.0

Open the chart page →

4,861
hive-metastoreolehrgfVerified publisher0.1.01 of 1See more

hive-metastore olehrgf 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-49568.

Container imageDigestPackageFixed in
ghcr.io/melodyyangaws/hive-metastore:3.0.0e949b0f733f0
gopkg.in/src-d/go-git.v4@v4.13.1
no fix listed

Open the chart page →

8,540
redhat-trusted-application-pipelineopenshift1.0.21 of 2See more

redhat-trusted-application-pipeline openshift 1.0.2

1 of the 2 container images this version deploys carry CVE-2023-49568.

Container imageDigestPackageFixed in
quay.io/redhat-appstudio/appstudio-utils:dbbdd82734232e6289e8fbae5b4c858481a7c0577b4202c25b67
github.com/go-git/go-git/v5@v5.3.0
5.11.0

Open the chart page →

8,599
npre-essentialsphntom0.1.601 of 22See more

npre-essentials phntom 0.1.60

1 of the 22 container images this version deploys carry CVE-2023-49568.

Container imageDigestPackageFixed in
quay.io/groundcover/grafana:9.3.18c65b333a3d3
github.com/go-git/go-git/v5@v5.4.2
5.11.0

Open the chart page →

26,840
hive-metastorepresto-loadbalancer0.2.31 of 1See more

hive-metastore presto-loadbalancer 0.2.3

1 of the 1 container images this version deploys carry CVE-2023-49568.

Container imageDigestPackageFixed in
datappeal/hive-metastore:lateste38c085a3567
gopkg.in/src-d/go-git.v4@v4.13.1
no fix listed

Open the chart page →

9,606
stackrox-chartredhat-cop0.0.101 of 1See more

stackrox-chart redhat-cop 0.0.10

1 of the 1 container images this version deploys carry CVE-2023-49568.

Container imageDigestPackageFixed in
quay.io/rht-labs/stack-do500:3.0.86ba82beff18e
gopkg.in/src-d/go-git.v4@v4.13.1
no fix listed

Open the chart page →

29,227
argocdromholdings1.8.11 of 3See more

argocd romholdings 1.8.1

1 of the 3 container images this version deploys carry CVE-2023-49568.

Container imageDigestPackageFixed in
argoproj/argocd:v1.8.1830e86cacefd
gopkg.in/src-d/go-git.v4@v4.13.1
no fix listed

Open the chart page →

10,466
devtron-enterpriseromholdings48.0.03 of 28See more

devtron-enterprise romholdings 48.0.0

3 of the 28 container images this version deploys carry CVE-2023-49568.

Container imageDigestPackageFixed in
quay.io/devtron/dex:v2.30.22e4c14d1b444
github.com/go-git/go-git/v5@v5.2.0
5.11.0
quay.io/devtron/image-scanner:94237c18-109-3942098580969b333
github.com/go-git/go-git/v5@v5.7.0
5.11.0
quay.io/devtron/kubectl:latest2ad610626658
github.com/go-git/go-git/v5@v5.4.2
5.11.0

Open the chart page →

68,240
devtron-in-clustercdromholdings0.10.21 of 2See more

devtron-in-clustercd romholdings 0.10.2

1 of the 2 container images this version deploys carry CVE-2023-49568.

Container imageDigestPackageFixed in
quay.io/devtron/kubewatch:49f906a5-419-14814eec0305b594c
github.com/go-git/go-git/v5@v5.6.1
5.11.0

Open the chart page →

5,039
devtron-operatorromholdings0.23.32 of 11See more

devtron-operator romholdings 0.23.3

2 of the 11 container images this version deploys carry CVE-2023-49568.

Container imageDigestPackageFixed in
quay.io/devtron/dex:v2.30.22e4c14d1b444
github.com/go-git/go-git/v5@v5.2.0
5.11.0
quay.io/devtron/kubectl:latest2ad610626658
github.com/go-git/go-git/v5@v5.4.2
5.11.0

Open the chart page →

32,902
loggensikalabs0.1.01 of 1See more

loggen sikalabs 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-49568.

Container imageDigestPackageFixed in
sikalabs/slu:v0.72.07bd267f30247
github.com/go-git/go-git/v5@v5.8.1
5.11.0

Open the chart page →

2,314
metrics-generatorsikalabs0.2.01 of 1See more

metrics-generator sikalabs 0.2.0

1 of the 1 container images this version deploys carry CVE-2023-49568.

Container imageDigestPackageFixed in
sikalabs/slu:v0.34.0fdc0c6711add
github.com/go-git/go-git/v5@v5.4.2
5.11.0

Open the chart page →

2,381
harborsoftonic1.13.01 of 8See more

harbor softonic 1.13.0

1 of the 8 container images this version deploys carry CVE-2023-49568.

Container imageDigestPackageFixed in
goharbor/trivy-adapter-photon:v2.9.0dc5b882a7db4
github.com/go-git/go-git/v5@v5.7.0
5.11.0

Open the chart page →

7,672
trivy-operatorsoftonic0.18.01 of 1See more

trivy-operator softonic 0.18.0

1 of the 1 container images this version deploys carry CVE-2023-49568.

Container imageDigestPackageFixed in
ghcr.io/aquasecurity/trivy-operator:0.16.0a608b798fda5
github.com/go-git/go-git/v5@v5.7.0
5.11.0

Open the chart page →

2,505
whitelisterstakaterVerified publisher0.0.161 of 1See more

whitelister stakater 0.0.16

1 of the 1 container images this version deploys carry CVE-2023-49568.

Container imageDigestPackageFixed in
stakater/whitelister:v0.0.1639107924063e
gopkg.in/src-d/go-git.v4@v4.13.1
no fix listed

Open the chart page →

2,564
workshop-operatorstakaterVerified publisher0.0.381 of 2See more

workshop-operator stakater 0.0.38

1 of the 2 container images this version deploys carry CVE-2023-49568.

Container imageDigestPackageFixed in
stakater/workshop-operator:v0.0.3897bf456cc97c
gopkg.in/src-d/go-git.v4@v4.13.1
no fix listed

Open the chart page →

6,671
sn-platform-slimstreamnative1.11.441 of 6See more

sn-platform-slim streamnative 1.11.44

1 of the 6 container images this version deploys carry CVE-2023-49568.

Container imageDigestPackageFixed in
streamnative/apache-pulsar-grafana-dashboard-k8s:0.1.20e6d7aa3ef32
github.com/go-git/go-git/v5@v5.4.2
5.11.0

Open the chart page →

10,134
grafanasvtech-public-helm-charts1.0.01 of 2See more

grafana svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2023-49568.

Container imageDigestPackageFixed in
svtechnmaa/svtech_grafana:v1.2.21d71314424aa
github.com/go-git/go-git/v5@v5.4.2
5.11.0

Open the chart page →

10,902
agentssynapse0.1.302 of 9See more

agents synapse 0.1.30

2 of the 9 container images this version deploys carry CVE-2023-49568.

Container imageDigestPackageFixed in
ghcr.io/synapsecns/sanguine/agents:6e3887fc2a05aff0d159453cedbfbe5024b910bf81a9ebc899a4
github.com/go-git/go-git/v5@v5.5.2
5.11.0
ghcr.io/synapsecns/sanguine/scribe:6e3887fc2a05aff0d159453cedbfbe5024b910bf5e0a3dfa9f96
github.com/go-git/go-git/v5@v5.5.2
5.11.0

Open the chart page →

7,244
cctpsynapse0.3.01 of 4See more

cctp synapse 0.3.0

1 of the 4 container images this version deploys carry CVE-2023-49568.

Container imageDigestPackageFixed in
ghcr.io/synapsecns/sanguine/cctp-relayer:b5a1dd5288f1a18eb05994e130d626fed45a56fc2f1408c94168
github.com/go-git/go-git/v5@v5.5.2
5.11.0

Open the chart page →

1,815
promexportersynapse0.1.11 of 1See more

promexporter synapse 0.1.1

1 of the 1 container images this version deploys carry CVE-2023-49568.

Container imageDigestPackageFixed in
ghcr.io/synapsecns/sanguine/promexporter:4a9aad096c2bd1160e56e5472ddac77fa0cde2e9416c1c5aeb86
github.com/go-git/go-git/v5@v5.5.2
5.11.0

Open the chart page →

1,704
ambassadorwenerme6.9.51 of 2See more

ambassador wenerme 6.9.5

1 of the 2 container images this version deploys carry CVE-2023-49568.

Container imageDigestPackageFixed in
datawire/aes:1.14.48588eafe6862
gopkg.in/src-d/go-git.v4@v4.13.1
no fix listed

Open the chart page →

4,086

Container images carrying it

74 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
quay.io/devtron/dex:v2.30.22e4c14d1b444
github.com/go-git/go-git/v5@v5.2.0
5.11.0
6
quay.io/devtron/kubectl:latest2ad610626658
github.com/go-git/go-git/v5@v5.4.2
5.11.0
6
argoproj/argocd:v1.8.1830e86cacefd
gopkg.in/src-d/go-git.v4@v4.13.1
no fix listed
3
quay.io/devtron/image-scanner:94237c18-109-3942098580969b333
github.com/go-git/go-git/v5@v5.7.0
5.11.0
3
quay.io/devtron/kubewatch:49f906a5-419-14814eec0305b594c
github.com/go-git/go-git/v5@v5.6.1
5.11.0
3
datawire/aes:1.14.48588eafe6862
gopkg.in/src-d/go-git.v4@v4.13.1
no fix listed
2
grafana/grafana:9.2.4057896e23443
github.com/go-git/go-git/v5@v5.4.2
5.11.0
2
mesosphere/kubeaddons-catalog:v0.11.4073db43d0b8b
github.com/go-git/go-git/v5@v5.1.0
5.11.0
2
streamnative/apache-pulsar-grafana-dashboard-k8s:0.1.20e6d7aa3ef32
github.com/go-git/go-git/v5@v5.4.2
5.11.0
2
ghcr.io/dexidp/dex:v2.28.15e88f2205de1
github.com/go-git/go-git/v5@v5.2.0
5.11.0
2
quay.io/groundcover/grafana:9.3.18c65b333a3d3
github.com/go-git/go-git/v5@v5.4.2
5.11.0
2
aquasec/harbor-scanner-trivy:0.20.07ea4aa3d2eb6
github.com/go-git/go-git/v5@v5.0.0
5.11.0
1
aquasec/trivy:0.43.1944a04445179
github.com/go-git/go-git/v5@v5.7.0
5.11.0
1
aquasec/trivy:0.32.0973d0df16189
github.com/go-git/go-git/v5@v5.4.2
5.11.0
1
chaosnative/cle-server:2.7.0e7bcff4a20c0
github.com/go-git/go-git/v5@v5.3.0
5.11.0
1
charmcli/soft-serve:v0.4.039523c1a6ba8
github.com/go-git/go-git/v5@v5.4.3-0.20210630082519-b4368b2a2ca4
5.11.0
1
datappeal/hive-metastore:lateste38c085a3567
gopkg.in/src-d/go-git.v4@v4.13.1
no fix listed
1
datawire/aes:2.0.3-ea07f8fe4f4f8e
gopkg.in/src-d/go-git.v4@v4.13.1
no fix listed
1
datawire/aes:1.13.62beb65062c8b
gopkg.in/src-d/go-git.v4@v4.13.1
no fix listed
1
devopstales/trivy-operator:2.575136aa7a26e
github.com/go-git/go-git/v5@v5.4.2
5.11.0
1
devspacecloud/manager:0.3.349c397413f7b
gopkg.in/src-d/go-git.v4@v4.13.1
no fix listed
1
epamedp/codebase-operator:2.12.0-MDTU-DDM-SNAPSHOT.1096028c86f0dd
github.com/go-git/go-git/v5@v5.4.3-0.20210630082519-b4368b2a2ca4
5.11.0
1
epamedp/edp-admin-console:2.14.0616c678ba3e7
gopkg.in/src-d/go-git.v4@v4.10.0
no fix listed
1
epamedp/gerrit-operator:2.11.0-MDTU-DDM-SNAPSHOT.2b71fb39e0c9e
github.com/go-git/go-git/v5@v5.4.2
5.11.0
1
epamedp/reconciler:2.12.0d33e938b6d59
github.com/go-git/go-git/v5@v5.4.3-0.20210630082519-b4368b2a2ca4
5.11.0
1
flanksource/apm-hub:v0.0.471dacc3195bf9
github.com/go-git/go-git/v5@v5.6.1
5.11.0
1
fluxcd/source-controller:v0.10.031a8c79a6803
github.com/go-git/go-git/v5@v5.2.0
5.11.0
1
gitea/gitea:1.12.485416d6f65fe
github.com/go-git/go-git/v5@v5.1.0
5.11.0
1
gitea/gitea:1.13.0d5ab14cd29af
github.com/go-git/go-git/v5@v5.1.0
5.11.0
1
goharbor/trivy-adapter-photon:v2.5.3b9522c3f5056
github.com/go-git/go-git/v5@v5.4.2
5.11.0
1
goharbor/trivy-adapter-photon:v2.9.0dc5b882a7db4
github.com/go-git/go-git/v5@v5.7.0
5.11.0
1
grafana/grafana:10.1.50679e877ba20
github.com/go-git/go-git/v5@v5.4.2
5.11.0
1
grafana/grafana:9.4.71a359d92f40e
github.com/go-git/go-git/v5@v5.4.2
5.11.0
1
grafana/grafana:10.1.11b9ca4bbc4a2
github.com/go-git/go-git/v5@v5.4.2
5.11.0
1
grafana/grafana:9.5.239c849cebccc
github.com/go-git/go-git/v5@v5.4.2
5.11.0
1
grafana/grafana:9.4.376dcf36e7d2a
github.com/go-git/go-git/v5@v5.4.2
5.11.0
1
grafana/grafana:9.1.19746858c20e6
github.com/go-git/go-git/v5@v5.4.2
5.11.0
1
hashicorp/waypoint:0.11.397d521a27498
github.com/go-git/go-git/v5@v5.2.0
gopkg.in/src-d/go-git.v4@v4.13.1
5.11.0
no fix listed
1
inseefrlab/shelly:cloudshell31f04ca7436b
gopkg.in/src-d/go-git.v4@v4.13.1
no fix listed
1
invisibl/gravity-init:v1.0.91a970f84178b
github.com/go-git/go-git/v5@v5.4.2
5.11.0
1
iotaledger/goshimmer:v0.8.6b02a8f77474f
gopkg.in/src-d/go-git.v4@v4.13.1
no fix listed
1
kubebb/oidc-server:v0.2.02b5894ef1e2f
github.com/go-git/go-git/v5@v5.4.2
5.11.0
1
layer5/meshery-consul:stable-latest25a4cc38abcd
github.com/go-git/go-git/v5@v5.9.0
5.11.0
1
layer5/meshery-osm:stable-latestec898e5786c6
github.com/go-git/go-git/v5@v5.4.2
5.11.0
1
layer5/meshery-traefik-mesh:stable-latest797fa7a03570
github.com/go-git/go-git/v5@v5.4.2
5.11.0
1
mesosphere/dex:v2.37.0-d2iq.1b093d78a21ed
github.com/go-git/go-git/v5@v5.4.2
5.11.0
1
mesosphere/kommander-federation-utility-apiserver:v0.21.2f9b769c65e24
github.com/go-git/go-git/v5@v5.2.0
gopkg.in/src-d/go-git.v4@v4.13.1
5.11.0
no fix listed
1
ntakashi/gitana:1.4.04171ec641120
github.com/go-git/go-git/v5@v5.4.2
5.11.0
1
owncloud/ocis:1.7.0d2efcae92c84
github.com/go-git/go-git/v5@v5.1.0
5.11.0
1
portainer/portainer-ce:2.18.4-alpine3e61aaee1341
github.com/go-git/go-git/v5@v5.3.0
5.11.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.