Known Vulnerabilities for Gitoxide by Gitoxide
Listed below are 10 of the newest known vulnerabilities associated with "Gitoxide" by "Gitoxide".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-82255 json | gitoxide versions from 0.25.4 contain an HTTP credential leak vulnerability in the curl-based transport backend where credent... | Not Provided | 2026-08-28 | 2026-08-28 |
| CVE-2026-82254 json | gitoxide before 0.69.0 contains unchecked array indexing in delta application and uncapped allocation from attacker-controlle... | Not Provided | 2026-08-28 | 2026-08-28 |
| CVE-2026-82253 json | gitoxide (Rust crates gix <= 0.72.0 and gix-validate <= 0.10.0) contains a path traversal vulnerability. The submodule name v... | Not Provided | 2026-08-28 | 2026-08-28 |
| CVE-2026-82252 json | gitoxide before 0.52.1 follows symlinks when reading the worktree .gitmodules file, allowing attackers to inject out-of-repos... | Not Provided | 2026-08-28 | 2026-08-28 |
| CVE-2026-82251 json | gitoxide before 0.52.1 fails to validate submodule names from .gitmodules configuration, allowing path traversal when derivin... | Not Provided | 2026-08-28 | 2026-08-28 |
| CVE-2026-82250 json | gitoxide gix-packetline versions before 0.21.5 contain a panic vulnerability in the TextRef implementation that occurs when p... | Not Provided | 2026-08-28 | 2026-08-28 |
| CVE-2026-82249 json | gitoxide before 0.38.2 fails to validate carriage return characters in URL values passed to credential helpers. Attackers can... | Not Provided | 2026-08-28 | 2026-08-28 |
| CVE-2026-82248 json | gix-worktree-state before 0.33.0 (part of gitoxide) allows writing files outside the worktree on Windows. gix_worktree_state:... | Not Provided | 2026-08-28 | 2026-08-28 |
| CVE-2026-82247 json | gitoxide's gix-url crate (<= 0.32.0, fixed in 0.37.1) uses a hand-rolled URL parser that does not treat '?' or '#' as termina... | Not Provided | 2026-08-28 | 2026-08-28 |
| CVE-2026-40034 json | gix-submodule before 0.29.0 (gitoxide before 0.5.21, gix before 0.84.0) incorrectly validates the update field in .gitmodules... | Not Provided | 2026-05-26 | 2026-07-14 |