Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-91986

Опубликовано: 15 сент. 2026
Источник: nvd
CVSS3: 5.4
EPSS Низкий

Описание

gitoxide gix-transport before 0.59.2 fails to filter control characters in git-daemon connect requests, allowing attackers to inject NUL/CR/LF bytes via crafted git URLs. Attackers can inject extra NUL-delimited protocol fields to spoof virtual hosts or inject newlines into daemon requests and logs.

EPSS

Процентиль: 11%
0.00203
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-74

Связанные уязвимости

CVSS3: 5.4
ubuntu
4 дня назад

(gitoxide gix-transport before 0.59.2 fails to filter control character ...)

CVSS3: 5.4
redhat
4 дня назад

gitoxide gix-transport before 0.59.2 fails to filter control characters in git-daemon connect requests, allowing attackers to inject NUL/CR/LF bytes via crafted git URLs. Attackers can inject extra NUL-delimited protocol fields to spoof virtual hosts or inject newlines into daemon requests and logs.

msrc
около 18 часов назад

gitoxide gix-transport before 0.59.2 CR/LF/NUL Injection

CVSS3: 5.4
debian
4 дня назад

gitoxide gix-transport before 0.59.2 fails to filter control character ...

CVSS3: 5.4
github
4 дня назад

gitoxide gix-transport before 0.59.2 fails to filter control characters in git-daemon connect requests, allowing attackers to inject NUL/CR/LF bytes via crafted git URLs. Attackers can inject extra NUL-delimited protocol fields to spoof virtual hosts or inject newlines into daemon requests and logs.

EPSS

Процентиль: 11%
0.00203
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-74