gitoxide gix-transport before 0.59.2 fails to filter control characters in git-daemon connect requests, allowing attackers to inject NUL/CR/LF bytes via crafted git URLs. Attackers can inject extra NUL-delimited protocol fields to spoof virtual hosts or inject newlines into daemon requests and logs.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 15 Sep 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | gitoxide gix-transport before 0.59.2 fails to filter control characters in git-daemon connect requests, allowing attackers to inject NUL/CR/LF bytes via crafted git URLs. Attackers can inject extra NUL-delimited protocol fields to spoof virtual hosts or inject newlines into daemon requests and logs. | |
| Title | gitoxide gix-transport before 0.59.2 CR/LF/NUL Injection | |
| First Time appeared |
Gitoxidelabs
Gitoxidelabs gitoxide |
|
| Weaknesses | CWE-74 | |
| CPEs | cpe:2.3:a:gitoxidelabs:gitoxide:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Gitoxidelabs
Gitoxidelabs gitoxide |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-15T15:18:28.963Z
Reserved: 2026-09-15T11:10:41.354Z
Link: CVE-2026-91986
No data.
Status : Received
Published: 2026-09-15T16:17:57.153
Modified: 2026-09-15T16:17:57.153
Link: CVE-2026-91986
No data.
OpenCVE Enrichment
No data.
Weaknesses