Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 15 Sep 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | gitoxide gix-transport before 0.59.2 fails to filter control characters in git-daemon connect requests, allowing attackers to inject NUL/CR/LF bytes via crafted git URLs. Attackers can inject extra NUL-delimited protocol fields to spoof virtual hosts or inject newlines into daemon requests and logs. | |
| Title | gitoxide gix-transport before 0.59.2 CR/LF/NUL Injection | |
| First Time appeared |
Gitoxidelabs
Gitoxidelabs gitoxide |
|
| Weaknesses | CWE-74 | |
| CPEs | cpe:2.3:a:gitoxidelabs:gitoxide:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Gitoxidelabs
Gitoxidelabs gitoxide |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-15T15:18:28.963Z
Reserved: 2026-09-15T11:10:41.354Z
Link: CVE-2026-91986
No data.
Status : Received
Published: 2026-09-15T16:17:57.153
Modified: 2026-09-15T16:17:57.153
Link: CVE-2026-91986
No data.
OpenCVE Enrichment
No data.
-
CWE-74
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')