CVE-2026-44740
Billy is an interface filesystem abstraction for Go. Prior to versions 5.9.0 and 6.0.0-alpha.1, multiple components may improperly handle crafted or malformed input, resulting in panics, infinite loops, uncontrolled recursion, or excessive resource consumption. These issues arise from insufficient validation and missing safety mechanisms such as cycle detection, recursion limits, or defensive handling of unexpected states when processing untrusted repository data and filesystem structures. This issue has been patched in versions 5.9.0 and 6.0.0-alpha.1.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- Puntuación base: 6.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.53%
- Percentil entre todas las CVEs puntuadas: 43
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
CWE
- CWE-674, CWE-835
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-44740",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-44740",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2026-06-01T18:13:54.236447Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 6.5,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "NONE"
},
"impactScore": 3.6,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "security-advisories@github.com",
"affectedData": [
{
"vendor": "go-git",
"product": "go-billy",
"versions": [
{
"status": "affected",
"version": "< 5.9.0"
},
{
"status": "affected",
"version": "< 6.0.0-alpha.1"
}
]
}
]
}
],
"published": "2026-06-01T17:17:08.277",
"references": [
{
"url": "https://github.com/go-git/go-billy/releases/tag/v5.9.0",
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/go-git/go-billy/releases/tag/v6.0.0-alpha.1",
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/go-git/go-billy/security/advisories/GHSA-m3xc-h892-ggx6",
"source": "security-advisories@github.com"
}
],
"vulnStatus": "Deferred",
"weaknesses": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"description": [
{
"lang": "en",
"value": "CWE-674"
},
{
"lang": "en",
"value": "CWE-835"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Billy is an interface filesystem abstraction for Go. Prior to versions 5.9.0 and 6.0.0-alpha.1, multiple components may improperly handle crafted or malformed input, resulting in panics, infinite loops, uncontrolled recursion, or excessive resource consumption. These issues arise from insufficient validation and missing safety mechanisms such as cycle detection, recursion limits, or defensive handling of unexpected states when processing untrusted repository data and filesystem structures. This issue has been patched in versions 5.9.0 and 6.0.0-alpha.1."
},
{
"lang": "es",
"value": "Billy es una abstracción de interfaz de sistema de archivos para Go. Antes de las versiones 5.9.0 y 6.0.0-alpha.1, múltiples componentes pueden manejar incorrectamente entradas manipuladas o malformadas, lo que resulta en panics, bucles infinitos, recursión incontrolada o consumo excesivo de recursos. Estos problemas surgen de una validación insuficiente y de la ausencia de mecanismos de seguridad como la detección de ciclos, límites de recursión o el manejo defensivo de estados inesperados al procesar datos de repositorio no confiables y estructuras de sistema de archivos. Este problema ha sido parcheado en las versiones 5.9.0 y 6.0.0-alpha.1."
}
],
"lastModified": "2026-07-22T07:10:00.107",
"sourceIdentifier": "security-advisories@github.com"
}