gitoxide gix-transport before 0.59.2 CR/LF/NUL Injection
Published Sep 15, 2026
5.3
MEDIUMCVSS 4.0
EPSS 0.23%
Description
gitoxide gix-transport before 0.59.2 fails to filter control characters in git-daemon connect requests, allowing attackers to inject NUL/CR/LF bytes via crafted git URLs. Attackers can inject extra NUL-delimited protocol fields to spoof virtual hosts or inject newlines into daemon requests and logs.
Affected products
-
- Version 0StatusaffectedConstraints<0.59.2
- Version 0.59.2StatusunaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| GitoxideLabs | Gitoxide | unaffected |
|
No data.
No data.
Red Hat Enterprise Linux 10
igvm
Fix deferred
Red Hat Enterprise Linux 10
rust
Fix deferred
Red Hat Enterprise Linux 8
rust-toolset:rhel8/rust
Fix deferred
Red Hat Enterprise Linux 9
rust
Fix deferred
Red Hat Enterprise Linux AI (RHEL AI) 3
rust
Fix deferred
Red Hat Hardened Images
openshell
Not affected
Red Hat Hardened Images
rust
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | igvm | Fix deferred | n/a |
| Red Hat Enterprise Linux 10 | rust | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | rust-toolset:rhel8/rust | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | rust | Fix deferred | n/a |
| Red Hat Enterprise Linux AI (RHEL AI) 3 | rust | Fix deferred | n/a |
| Red Hat Hardened Images | openshell | Not affected | n/a |
| Red Hat Hardened Images | rust | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (7)
- https://access.redhat.com/security/cve/CVE-2026-91986 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2533967 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-78657 Advisory
- https://github.com/GitoxideLabs/gitoxide/security/advisories/GHSA-rc7h-wp5f-w3g5 exploitvendor-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-91986
- https://www.cve.org/CVERecord?id=CVE-2026-91986
- https://www.vulncheck.com/advisories/gitoxide-gix-transport-before-0.59.2-cr-lf-nul-injection third-party-advisory
Change history (0)
No recorded changes yet.