Description
gitoxide gix-transport before 0.59.2 fails to filter control characters in git-daemon connect requests, allowing attackers to inject NUL/CR/LF bytes via crafted git URLs. Attackers can inject extra NUL-delimited protocol fields to spoof virtual hosts or inject newlines into daemon requests and logs.
Published: 2026-09-15
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Log injection
Action: Apply Patch
AI Analysis

Impact

gitoxide gix-transport versions before 0.59.2 does not filter CR, LF, or NUL bytes in git‑daemon connection requests, enabling attackers to inject crafted protocol fields into the transport layer. The injected NUL‑delimited fields can spoof virtual host names or introduce newlines into daemon communication and server logs, potentially corrupting log integrity and allowing misleading information to appear in audit affects GitoxideLabs’ gitoxide gix‑transport component in any version prior to 0.59.2.

Affected Systems

GitoxideLabs’s gitoxide gix‑transport component, any version before 0.59.2, is vulnerable. All installations of gitoxide on the affected CR.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate risk; the EPSS score is < 1%, which reflects a very low but non-zero exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is a remote attacker able to supply a maliciously crafted git URL to a reachable git‑daemon service, which then processes the injected control characters. Since the issue is limited to transport‑level filtering, exploitation would not automatically lead to code execution but could manipulate log data or host identification, which might be used in subsequent attacks. No public exploits have been disclosed to date.

Generated by OpenCVE AI on September 20, 2026 at 16:14 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade gitoxide to version 0.59.2 or later, which applies the transport‑level filtering fix.
  • Restrict external access to trusted networks can connect, thereby limiting the opportunity for a crafted URL to reach the vulnerable component.
  • Verify existing logs for unexpected CR, LF, or NUL characters and review any entries that appear to be malformed or injected.

Generated by OpenCVE AI on September 20, 2026 at 16:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-93
References
Metrics threat_severity

None

threat_severity

Moderate


Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Description gitoxide gix-transport before 0.59.2 fails to filter control characters in git-daemon connect requests, allowing attackers to inject NUL/CR/LF bytes via crafted git URLs. Attackers can inject extra NUL-delimited protocol fields to spoof virtual hosts or inject newlines into daemon requests and logs.
Title gitoxide gix-transport before 0.59.2 CR/LF/NUL Injection
First Time appeared Gitoxidelabs
Gitoxidelabs gitoxide
Weaknesses CWE-74
CPEs cpe:2.3:a:gitoxidelabs:gitoxide:*:*:*:*:*:*:*:*
Vendors & Products Gitoxidelabs
Gitoxidelabs gitoxide
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Gitoxidelabs Gitoxide
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-21T19:22:09.322Z

Reserved: 2026-09-15T11:10:41.354Z

Link: CVE-2026-91986

cve-icon Vulnrichment

Updated: 2026-09-21T19:21:11.016Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T16:17:57.153

Modified: 2026-09-23T17:17:45.270

Link: CVE-2026-91986

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-15T15:18:28Z

Links: CVE-2026-91986 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T16:15:18Z

Weaknesses
  • CWE-74

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

  • CWE-93

    Improper Neutralization of CRLF Sequences ('CRLF Injection')