Skip to main content
Version: v1.1.x

CVE-2026-44740

CVE Details

Visit the official vulnerability details page for CVE-2026-44740 to learn more.

Initial Publication

06/01/2026

Last Update

06/01/2026

Third Party Dependency

github.com/go-git/go-billy/v5

NIST CVE Summary

Billy is an interface filesystem abstraction for Go. Prior to versions 5.9.0 and 6.0.0-alpha.1, multiple components may improperly handle crafted or malformed input, resulting in panics, infinite loops, uncontrolled recursion, or excessive resource consumption. These issues arise from insufficient validation and missing safety mechanisms such as cycle detection, recursion limits, or defensive handling of unexpected states when processing untrusted repository data and filesystem structures. This issue has been patched in versions 5.9.0 and 6.0.0-alpha.1.

CVE Severity

6.5

Our Official Summary

Investigation is ongoing to determine how this vulnerability affects our products.

Status

Deferred

Affected Products & Versions

VersionPaletteAIPaletteAI VerteX
1.1.3⚠️ Impacted⚠️ Impacted
1.0.7⚠️ Impacted⚠️ Impacted

Revision History

No revisions available.