Impact
gitoxide gix-transport versions before 0.59.2 does not filter CR, LF, or NUL bytes in git‑daemon connection requests, enabling attackers to inject crafted protocol fields into the transport layer. The injected NUL‑delimited fields can spoof virtual host names or introduce newlines into daemon communication and server logs, potentially corrupting log integrity and allowing misleading information to appear in audit affects GitoxideLabs’ gitoxide gix‑transport component in any version prior to 0.59.2.
Affected Systems
GitoxideLabs’s gitoxide gix‑transport component, any version before 0.59.2, is vulnerable. All installations of gitoxide on the affected CR.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate risk; the EPSS score is < 1%, which reflects a very low but non-zero exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is a remote attacker able to supply a maliciously crafted git URL to a reachable git‑daemon service, which then processes the injected control characters. Since the issue is limited to transport‑level filtering, exploitation would not automatically lead to code execution but could manipulate log data or host identification, which might be used in subsequent attacks. No public exploits have been disclosed to date.
OpenCVE Enrichment