Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-xw8c-rrvx-f7xq | ciguard: SCA HTTP client reads response body without size cap |
Wed, 13 May 2026 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Jo-jo98
Jo-jo98 ciguard |
|
| Vendors & Products |
Jo-jo98
Jo-jo98 ciguard |
Tue, 12 May 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ciguard is a static security auditor for CI/CD pipelines. From 0.6.0 to 0.8.1, both SCA HTTP clients (src/ciguard/analyzer/sca/osv.py and src/ciguard/analyzer/sca/endoflife.py) call payload = json.loads(resp.read().decode('utf-8')) without a maximum-bytes cap. A hostile or compromised endoflife.date / OSV.dev (or a successful TLS MITM) could return a multi-GB response, exhausting the ciguard process's memory. This vulnerability is fixed in 0.8.2. | |
| Title | ciguard: SCA HTTP client reads response body without size cap | |
| Weaknesses | CWE-770 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-05-13T14:20:04.224Z
Reserved: 2026-05-05T15:42:40.517Z
Link: CVE-2026-44219
No data.
Status : Deferred
Published: 2026-05-12T20:16:42.767
Modified: 2026-05-13T17:02:28.447
Link: CVE-2026-44219
No data.
OpenCVE Enrichment
Updated: 2026-05-13T10:36:16Z
Github GHSA