Loading HuntDB...

GHSA-8fcj-gf77-47mg

GitHub Security Advisory

Denial of service (DoS) when processing Git credentials

✓ GitHub Reviewed MODERATE Has CVE

Advisory Details

### Impact

A denial of services (DoS) vulnerability was discovered in Wrangler Git package affecting versions up to and including `v1.0.0`.

Specially crafted Git credentials can result in a denial of service (DoS) attack on an application that uses Wrangler due to the exhaustion of the available memory and CPU resources. This is caused by a lack of input validation of Git credentials before they are used, which may lead to a denial of service in some cases. This issue can be triggered when accessing both private and public Git repositories.

### Workarounds

A workaround is to sanitize input passed to the Git package to remove potential unsafe and ambiguous characters. Otherwise, the best course of action is to update to a patched Wrangler version.

### Patches

Patched versions include `v1.0.1` and later and the backported tags - `v0.7.4-security1`, `v0.8.5-security1` and `v0.8.11`.

### For more information

If you have any questions or comments about this advisory:

* Reach out to [SUSE Rancher Security team](https://github.com/rancher/rancher/security/policy) for security related inquiries.
* Open an issue in [Rancher](https://github.com/rancher/rancher/issues/new/choose) or [Wrangler](https://github.com/rancher/wrangler/issues/new) repository.
* Verify our [support matrix](https://www.suse.com/suse-rancher/support-matrix/all-supported-versions/) and [product support lifecycle](https://www.suse.com/lifecycle/).

Affected Packages

Go github.com/rancher/wrangler
Affected versions: 0 (fixed in 0.7.4-security1)
Go github.com/rancher/wrangler
Affected versions: 0.8.0 (fixed in 0.8.5-security1)
Go github.com/rancher/wrangler
Affected versions: 1.0.0 (fixed in 1.0.1)
Go github.com/rancher/wrangler
Affected versions: 0.8.6 (fixed in 0.8.11)

Related CVEs

Key Information

GHSA ID
GHSA-8fcj-gf77-47mg
Published
January 25, 2023 7:40 PM
Last Modified
February 7, 2023 3:50 PM
CVSS Score
5.0 /10
Primary Ecosystem
Go
Primary Package
github.com/rancher/wrangler
GitHub Reviewed
✓ Yes

Dataset

Last updated: September 12, 2025 6:34 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.