GitoxideLabs gitoxide
12 known vulnerabilities in GitoxideLabs gitoxide, with patch priority, exploit likelihood and the news covering them.
Latest vulnerabilities
- CVE-2026-100419 CVSS 7.3 high gitoxide gix-fs before 0.23.0 contains a path validation bypass vulnerability in the worktree checkout mechanism that allows attackers to…
- CVE-2026-91986 CVSS 5.3 medium gitoxide gix-transport before 0.59.2 fails to filter control characters in git-daemon connect requests, allowing attackers to inject…
- CVE-2025-24890 CVSS 6.8 medium gitoxide is an implementation of git written in Rust. Prior to 0.13.3, the gix-sec crate on Windows incorrectly treats repositories…
- CVE-2026-82255 CVSS 7.6 high gitoxide versions from 0.25.4 contain an HTTP credential leak vulnerability in the curl-based transport backend where credentials are sent…
- CVE-2026-82254 CVSS 8.7 high gitoxide before 0.69.0 contains unchecked array indexing in delta application and uncapped allocation from attacker-controlled size…
- CVE-2026-82253 CVSS 8.7 high gitoxide (Rust crates gix <= 0.72.0 and gix-validate <= 0.10.0) contains a path traversal vulnerability. The submodule name validation…
- CVE-2026-82252 CVSS 8.7 high gitoxide before 0.52.1 follows symlinks when reading the worktree .gitmodules file, allowing attackers to inject out-of-repository bytes…
- CVE-2026-82251 CVSS 8.7 high gitoxide before 0.52.1 fails to validate submodule names from .gitmodules configuration, allowing path traversal when deriving submodule…
- CVE-2026-82250 CVSS 7.1 high gitoxide gix-packetline versions before 0.21.5 contain a panic vulnerability in the TextRef implementation that occurs when processing…
- CVE-2026-82249 CVSS 2.3 low gitoxide before 0.38.2 fails to validate carriage return characters in URL values passed to credential helpers. Attackers can supply URLs…
- CVE-2026-82248 CVSS 6.0 medium gix-worktree-state before 0.33.0 (part of gitoxide) allows writing files outside the worktree on Windows. gix_worktree_state::checkout()…
- CVE-2026-82247 CVSS 8.7 high gitoxide's gix-url crate (<= 0.32.0, fixed in 0.37.1) uses a hand-rolled URL parser that does not treat '?' or '#' as terminating the…