CVE-2026-100419
- EPSS 0.15%
- Veröffentlicht 25.09.2026 22:04:00
- Zuletzt bearbeitet 28.09.2026 14:17:09
gitoxide gix-fs before 0.23.0 contains a path validation bypass vulnerability in the worktree checkout mechanism that allows attackers to escape the worktree directory via symlink manipulation. During forced checkout with overwrite_existing enabled, ...
CVE-2026-91986
- EPSS 0.2%
- Veröffentlicht 15.09.2026 15:18:28
- Zuletzt bearbeitet 23.09.2026 17:17:45
gitoxide gix-transport before 0.59.2 fails to filter control characters in git-daemon connect requests, allowing attackers to inject NUL/CR/LF bytes via crafted git URLs. Attackers can inject extra NUL-delimited protocol fields to spoof virtual hosts...
CVE-2025-24890
- EPSS 0.15%
- Veröffentlicht 14.09.2026 15:28:03
- Zuletzt bearbeitet 23.09.2026 17:17:44
gitoxide is an implementation of git written in Rust. Prior to 0.13.3, the gix-sec crate on Windows incorrectly treats repositories controlled by another user as trusted when an administrator runs a dependent program with an unfiltered elevated token...
CVE-2026-82254
- EPSS 0.35%
- Veröffentlicht 28.08.2026 10:49:38
- Zuletzt bearbeitet 28.08.2026 18:54:09
gitoxide before 0.69.0 contains unchecked array indexing in delta application and uncapped allocation from attacker-controlled size headers in gix-pack. Attackers can send crafted pack data during clone or fetch operations to trigger panics or out-of...
CVE-2026-82255
- EPSS 0.23%
- Veröffentlicht 28.08.2026 10:49:38
- Zuletzt bearbeitet 30.09.2026 18:18:41
gitoxide versions from 0.25.4 contain an HTTP credential leak vulnerability in the curl-based transport backend where credentials are sent to attacker-controlled servers after HTTP redirects. The vulnerability occurs because credential validation che...
CVE-2026-82253
- EPSS 0.5%
- Veröffentlicht 28.08.2026 10:49:37
- Zuletzt bearbeitet 31.08.2026 19:17:16
gitoxide (Rust crates gix <= 0.72.0 and gix-validate <= 0.10.0) contains a path traversal vulnerability. The submodule name validation function in gix-validate only checks the first occurrence of '..' via name.find(b".."), allowing crafted names such...
CVE-2026-82251
- EPSS 0.39%
- Veröffentlicht 28.08.2026 10:49:36
- Zuletzt bearbeitet 29.08.2026 14:16:37
gitoxide before 0.52.1 fails to validate submodule names from .gitmodules configuration, allowing path traversal when deriving submodule git directories. Attackers can craft malicious submodule names with traversal segments to redirect state() and op...
CVE-2026-82252
- EPSS 0.39%
- Veröffentlicht 28.08.2026 10:49:36
- Zuletzt bearbeitet 29.08.2026 14:16:37
gitoxide before 0.52.1 follows symlinks when reading the worktree .gitmodules file, allowing attackers to inject out-of-repository bytes into submodule metadata. Attackers can create a malicious repository with a symlinked .gitmodules pointing outsid...
CVE-2026-82250
- EPSS 0.24%
- Veröffentlicht 28.08.2026 10:49:35
- Zuletzt bearbeitet 28.08.2026 20:20:16
gitoxide gix-packetline versions before 0.21.5 contain a panic vulnerability in the TextRef implementation that occurs when processing side-band packet lines with empty payloads. A malicious Git server can send a crafted side-band packet to trigger a...
- EPSS 0.23%
- Veröffentlicht 28.08.2026 10:49:34
- Zuletzt bearbeitet 31.08.2026 19:17:16
gix-worktree-state before 0.33.0 (part of gitoxide) allows writing files outside the worktree on Windows. gix_worktree_state::checkout() follows an existing terminal symlink during non-exclusive (incremental) materialization (destination_is_initially...