Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

gitoxide — Vulnerabilities & Security Advisories 24

All 24 CVE vulnerabilities found in gitoxide, with AI-generated Chinese analysis, references, and POCs.

This page documents security weaknesses affecting gitoxide, a fast, safe, and correct Git library implementation for the Rust programming language, categorized under common weakness types such as buffer overflows and memory safety violations. The collection aggregates vulnerability data derived from vendor advisories, issue trackers, and independent security research, covering incidents reported from the project’s initial public release through the current date. By consulting this resource, users can track the evolution of a vendor’s advisory response patterns, gain a deeper understanding of specific weakness classes inherent to systems programming in Rust, and lookup the detailed vulnerability history of the product to assess its current security posture. The content focuses on identifying how specific coding errors or dependency issues have manifested in real-world scenarios, providing context on severity, impact, and resolution timelines without relying on external metadata. This structured approach allows developers and security auditors to evaluate the robustness of gitoxide’s codebase and its adherence to secure development practices over time. The page serves as a neutral repository of factual findings, aiming to inform decision-making regarding the integration or maintenance of the software within larger infrastructure environments. All entries are sourced from verified public records to ensure accuracy and traceability, supporting transparency in open-source security management.

Vendor: Byron

CVE ID Title CVSS Severity Published
CVE-2026-100419 gitoxide gix-fs before 0.23.0 Worktree Escape via Symlink CWE-59 7.0 High 2026-09-25
CVE-2026-91986 gitoxide gix-transport before 0.59.2 CR/LF/NUL Injection CWE-74 5.4 Medium 2026-09-15
CVE-2025-24890 gix-sec safe.directory protections absent for elevated administrators CWE-283 6.8 Medium 2026-09-14
CVE-2026-82255 gitoxide 0.25.4 HTTP Credential Leak via Redirect CWE-522 6.8 Medium 2026-08-28
CVE-2026-82254 gitoxide before 0.69.0 Denial of Service via gix-pack CWE-248 7.5 High 2026-08-28
CVE-2026-82253 gitoxide before 0.82.0 Path Traversal via Submodule Name Validation Bypass CWE-22 7.5 High 2026-08-28
CVE-2026-82252 gitoxide before 0.52.1 Repository Boundary Violation via symlinked .gitmodules CWE-59 7.5 High 2026-08-28
CVE-2026-82251 gitoxide before 0.52.1 Path Traversal via Submodule Name CWE-22 7.5 High 2026-08-28
CVE-2026-82250 gitoxide gix-packetline before 0.21.5 Denial of Service CWE-191 6.5 Medium 2026-08-28
CVE-2026-82249 gitoxide before 0.38.2 Credential Helper Protocol Field Injection CWE-116 3.1 Low 2026-08-28
CVE-2026-82248 gitoxide before 0.33.0 Path Traversal via symlink following CWE-59 5.3 Medium 2026-08-28
CVE-2026-82247 gitoxide before 0.37.1 HTTP Basic credential leak via URL parsing CWE-522 7.5 High 2026-08-28
CVE-2026-40034 gitoxide - Command Injection via Partial .gitmodules Override in gix-submodule CWE-77 7.8 High 2026-05-26
CVE-2026-44471 gitoxide: Symlink prefix-reuse allows worktree escape during checkout CWE-59 7.8 High 2026-05-13
CVE-2026-0810 Gix-date: gix-date: undefined behavior due to invalid string generation CWE-135 7.1 High 2026-01-26
CVE-2025-31130 gitoxide does not detect SHA-1 collision attacks CWE-328 6.8 Medium 2025-04-04
CVE-2025-22620 gix-worktree-state nonexclusive checkout sets executable files world-writable CWE-281 5.0 Medium 2025-01-20
CVE-2024-45405 gix-path improperly resolves configuration path reported by Git CWE-41 6.0 Medium 2024-09-06
CVE-2024-45305 gix-path uses local config across repos when it is the highest scope CWE-706 2.5 Low 2024-09-02
CVE-2024-43785 gitoxide-core does not neutralize special characters for terminals CWE-150 2.5 Low 2024-08-22
CVE-2024-40644 gitoxide's gix-path can use a fake program files location CWE-345 6.8 Medium 2024-07-18
CVE-2024-35197 gix refs and paths with reserved Windows device names access the devices CWE-67 5.4 Medium 2024-05-23
CVE-2024-35186 gix traversal outside working tree enables arbitrary code execution CWE-23 8.8 High 2024-05-23
CVE-2024-32884 gix-transport indirect code execution via malicious username CWE-77 6.4 Medium 2024-04-26

All 24 known CVE vulnerabilities affecting gitoxide with full Chinese analysis, references, and POCs where available.