Impact
The vulnerability in Gitoxide before version 0.69.0 arises from unchecked array indexing in delta application and uncapped allocation based on attacker‑controlled size headers in gix-pack. These issues allow an attacker to send specially crafted pack data that can trigger runtime panics or cause the process to run out of memory, resulting in a denial of service.
Affected Systems
Affected systems include installations of GitoxideLabs Gitoxide prior to 0.69.0. The flaw is present in the repository management tool used for clone or fetch operations.
Risk and Exploitability
The CVSS score of 8.7 indicates high severity. The EPSS score is not available and the vulnerability is not listed in CISA KEV. Attackers can exploit the flaw by supplying malicious pack data over the network during clone or fetch operations, which is a remote attack vector inferred from the description. If not mitigated, an attacker could force the Gitoxide process to terminate, disrupting service availability. The lack of an official fix in the provided data suggests administrators should check for security updates or restrict access to the Gitoxide service.
OpenCVE Enrichment