Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7849-h6h3-vww8

Опубликовано: 15 сент. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 5.3
CVSS3: 5.4

Описание

gitoxide gix-transport before 0.59.2 fails to filter control characters in git-daemon connect requests, allowing attackers to inject NUL/CR/LF bytes via crafted git URLs. Attackers can inject extra NUL-delimited protocol fields to spoof virtual hosts or inject newlines into daemon requests and logs.

gitoxide gix-transport before 0.59.2 fails to filter control characters in git-daemon connect requests, allowing attackers to inject NUL/CR/LF bytes via crafted git URLs. Attackers can inject extra NUL-delimited protocol fields to spoof virtual hosts or inject newlines into daemon requests and logs.

EPSS

Процентиль: 11%
0.00203
Низкий

5.3 Medium

CVSS4

5.4 Medium

CVSS3

Дефекты

CWE-74

Связанные уязвимости

CVSS3: 5.4
ubuntu
4 дня назад

(gitoxide gix-transport before 0.59.2 fails to filter control character ...)

CVSS3: 5.4
redhat
4 дня назад

gitoxide gix-transport before 0.59.2 fails to filter control characters in git-daemon connect requests, allowing attackers to inject NUL/CR/LF bytes via crafted git URLs. Attackers can inject extra NUL-delimited protocol fields to spoof virtual hosts or inject newlines into daemon requests and logs.

CVSS3: 5.4
nvd
4 дня назад

gitoxide gix-transport before 0.59.2 fails to filter control characters in git-daemon connect requests, allowing attackers to inject NUL/CR/LF bytes via crafted git URLs. Attackers can inject extra NUL-delimited protocol fields to spoof virtual hosts or inject newlines into daemon requests and logs.

msrc
около 18 часов назад

gitoxide gix-transport before 0.59.2 CR/LF/NUL Injection

CVSS3: 5.4
debian
4 дня назад

gitoxide gix-transport before 0.59.2 fails to filter control character ...

EPSS

Процентиль: 11%
0.00203
Низкий

5.3 Medium

CVSS4

5.4 Medium

CVSS3

Дефекты

CWE-74