Description
gitoxide before 0.69.0 contains unchecked array indexing in delta application and uncapped allocation from attacker-controlled size headers in gix-pack. Attackers can send crafted pack data during clone or fetch operations to trigger panics or out-of-memory process kills.
Published: 2026-08-28
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Patch Now
AI Analysis

Impact

The vulnerability in Gitoxide before version 0.69.0 arises from unchecked array indexing in delta application and uncapped allocation based on attacker‑controlled size headers in gix-pack. These issues allow an attacker to send specially crafted pack data that can trigger runtime panics or cause the process to run out of memory, resulting in a denial of service.

Affected Systems

Affected systems include installations of GitoxideLabs Gitoxide prior to 0.69.0. The flaw is present in the repository management tool used for clone or fetch operations.

Risk and Exploitability

The CVSS score of 8.7 indicates high severity. The EPSS score is not available and the vulnerability is not listed in CISA KEV. Attackers can exploit the flaw by supplying malicious pack data over the network during clone or fetch operations, which is a remote attack vector inferred from the description. If not mitigated, an attacker could force the Gitoxide process to terminate, disrupting service availability. The lack of an official fix in the provided data suggests administrators should check for security updates or restrict access to the Gitoxide service.

Generated by OpenCVE AI on August 28, 2026 at 13:18 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to Gitoxide version 0.69.0 or later once an official patch is released.
  • If a patch is unavailable, limit exposure by restricting network access to the Gitoxide service to trusted hosts only.
  • Monitor Gitoxide logs for unexpected panics or memory usage spikes and plan for mitigation.

Generated by OpenCVE AI on August 28, 2026 at 13:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 28 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 28 Aug 2026 11:30:00 +0000

Type Values Removed Values Added
Description gitoxide before 0.69.0 contains unchecked array indexing in delta application and uncapped allocation from attacker-controlled size headers in gix-pack. Attackers can send crafted pack data during clone or fetch operations to trigger panics or out-of-memory process kills.
Title gitoxide before 0.69.0 Denial of Service via gix-pack
First Time appeared Gitoxidelabs
Gitoxidelabs gitoxide
Weaknesses CWE-248
CPEs cpe:2.3:a:gitoxidelabs:gitoxide:*:*:*:*:*:*:*:*
Vendors & Products Gitoxidelabs
Gitoxidelabs gitoxide
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Gitoxidelabs Gitoxide
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-08-28T13:59:07.704Z

Reserved: 2026-08-28T10:39:30.355Z

Link: CVE-2026-82254

cve-icon Vulnrichment

Updated: 2026-08-28T13:59:00.660Z

cve-icon NVD

Status : Deferred

Published: 2026-08-28T12:16:38.173

Modified: 2026-08-28T18:54:09.323

Link: CVE-2026-82254

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T15:30:07Z

Weaknesses