Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-91986

Опубликовано: 15 сент. 2026
Источник: debian
EPSS Низкий

Описание

gitoxide gix-transport before 0.59.2 fails to filter control characters in git-daemon connect requests, allowing attackers to inject NUL/CR/LF bytes via crafted git URLs. Attackers can inject extra NUL-delimited protocol fields to spoof virtual hosts or inject newlines into daemon requests and logs.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
rust-gix-transportunfixedpackage

Примечания

  • https://github.com/GitoxideLabs/gitoxide/security/advisories/GHSA-rc7h-wp5f-w3g5

EPSS

Процентиль: 11%
0.00203
Низкий

Связанные уязвимости

CVSS3: 5.4
ubuntu
4 дня назад

(gitoxide gix-transport before 0.59.2 fails to filter control character ...)

CVSS3: 5.4
redhat
4 дня назад

gitoxide gix-transport before 0.59.2 fails to filter control characters in git-daemon connect requests, allowing attackers to inject NUL/CR/LF bytes via crafted git URLs. Attackers can inject extra NUL-delimited protocol fields to spoof virtual hosts or inject newlines into daemon requests and logs.

CVSS3: 5.4
nvd
4 дня назад

gitoxide gix-transport before 0.59.2 fails to filter control characters in git-daemon connect requests, allowing attackers to inject NUL/CR/LF bytes via crafted git URLs. Attackers can inject extra NUL-delimited protocol fields to spoof virtual hosts or inject newlines into daemon requests and logs.

msrc
около 18 часов назад

gitoxide gix-transport before 0.59.2 CR/LF/NUL Injection

CVSS3: 5.4
github
4 дня назад

gitoxide gix-transport before 0.59.2 fails to filter control characters in git-daemon connect requests, allowing attackers to inject NUL/CR/LF bytes via crafted git URLs. Attackers can inject extra NUL-delimited protocol fields to spoof virtual hosts or inject newlines into daemon requests and logs.

EPSS

Процентиль: 11%
0.00203
Низкий