Impact
gitoxide gix-packetline versions prior to 0.21.5 contain a panic vulnerability in the TextRef implementation. When a side-band packet line with an empty payload is processed, an index out of bounds error causes the client to panic and abort. This results in a denial of service for the target process during fetch operations, and the flaw is triggered without requiring authentication.
Affected Systems
The affected product is GitoxideLabs' gitoxide library. All releases before 0.21.5 are vulnerable and may be used in any Git client that relies on this library.
Risk and Exploitability
The CVSS score of 7.1 places this flaw in the medium‑to‑high severity range. The EPSS score is not available, and it is not listed in the CISA KEV catalog. A malicious Git server can craft a side-band packet with an empty payload and send it to a vulnerable client during a fetch. No credentials are needed, so the vulnerability can be exploited remotely over a network connection that the client trusts.
OpenCVE Enrichment