Количество 6
Количество 6
CVE-2026-91986
(gitoxide gix-transport before 0.59.2 fails to filter control character ...)
CVE-2026-91986
gitoxide gix-transport before 0.59.2 fails to filter control characters in git-daemon connect requests, allowing attackers to inject NUL/CR/LF bytes via crafted git URLs. Attackers can inject extra NUL-delimited protocol fields to spoof virtual hosts or inject newlines into daemon requests and logs.
CVE-2026-91986
gitoxide gix-transport before 0.59.2 fails to filter control characters in git-daemon connect requests, allowing attackers to inject NUL/CR/LF bytes via crafted git URLs. Attackers can inject extra NUL-delimited protocol fields to spoof virtual hosts or inject newlines into daemon requests and logs.
CVE-2026-91986
gitoxide gix-transport before 0.59.2 CR/LF/NUL Injection
CVE-2026-91986
gitoxide gix-transport before 0.59.2 fails to filter control character ...
GHSA-7849-h6h3-vww8
gitoxide gix-transport before 0.59.2 fails to filter control characters in git-daemon connect requests, allowing attackers to inject NUL/CR/LF bytes via crafted git URLs. Attackers can inject extra NUL-delimited protocol fields to spoof virtual hosts or inject newlines into daemon requests and logs.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-91986 (gitoxide gix-transport before 0.59.2 fails to filter control character ...) | CVSS3: 5.4 | 0% Низкий | 4 дня назад | |
CVE-2026-91986 gitoxide gix-transport before 0.59.2 fails to filter control characters in git-daemon connect requests, allowing attackers to inject NUL/CR/LF bytes via crafted git URLs. Attackers can inject extra NUL-delimited protocol fields to spoof virtual hosts or inject newlines into daemon requests and logs. | CVSS3: 5.4 | 0% Низкий | 4 дня назад | |
CVE-2026-91986 gitoxide gix-transport before 0.59.2 fails to filter control characters in git-daemon connect requests, allowing attackers to inject NUL/CR/LF bytes via crafted git URLs. Attackers can inject extra NUL-delimited protocol fields to spoof virtual hosts or inject newlines into daemon requests and logs. | CVSS3: 5.4 | 0% Низкий | 4 дня назад | |
CVE-2026-91986 gitoxide gix-transport before 0.59.2 CR/LF/NUL Injection | 0% Низкий | около 19 часов назад | ||
CVE-2026-91986 gitoxide gix-transport before 0.59.2 fails to filter control character ... | CVSS3: 5.4 | 0% Низкий | 4 дня назад | |
GHSA-7849-h6h3-vww8 gitoxide gix-transport before 0.59.2 fails to filter control characters in git-daemon connect requests, allowing attackers to inject NUL/CR/LF bytes via crafted git URLs. Attackers can inject extra NUL-delimited protocol fields to spoof virtual hosts or inject newlines into daemon requests and logs. | CVSS3: 5.4 | 0% Низкий | 4 дня назад |
Уязвимостей на страницу