GHSA-f786-75f3-74xj

Suggest an improvement
Source
https://github.com/advisories/GHSA-f786-75f3-74xj
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/11/GHSA-f786-75f3-74xj/GHSA-f786-75f3-74xj.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-f786-75f3-74xj
Aliases
Published
2025-11-20T18:31:00Z
Modified
2025-11-20T22:27:41.198339Z
Severity
  • 1.9 (Low) CVSS_V4 - CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L/E:P CVSS Calculator
Summary
OSV-SCALIBR has NULL Pointer Dereference
Details

A bug in the filesystem traversal fallback path causes fs/diriterate/diriterate.go:Next() to overindex an empty slice when ReadDir returns nil for an empty directory, resulting in a panic (index out of range) and an application crash (denial of service) in OSV-SCALIBR.

Database specific
{
    "severity": "LOW",
    "github_reviewed": true,
    "cwe_ids": [
        "CWE-476"
    ],
    "nvd_published_at": "2025-11-20T16:15:56Z",
    "github_reviewed_at": "2025-11-20T21:45:51Z"
}
References

Affected packages

Go / github.com/google/osv-scalibr

Package

Name
github.com/google/osv-scalibr
View open source insights on deps.dev
Purl
pkg:golang/github.com/google/osv-scalibr

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.3.4