Credential Leakage via URL Parsing in Gitoxide's gix-url Crate
CVE-2026-82247

8.7HIGH

Key Information:

Status
Vendor
CVE Published:
28 August 2026

What is CVE-2026-82247?

The gix-url crate in Gitoxide shows a significant vulnerability due to its improper URL parsing, specifically regarding the treatment of '?' and '#' in the authority component, contrary to RFC 3986 specifications. This flaw allows attackers to manipulate HTTP redirect responses, leading to the potential leakage of HTTP Basic Authorization credentials to unintended hosts. The issue affects versions up to and including 0.32.0 of gix-url and 0.49.0 of gix-transport but has been addressed in subsequent releases.

Affected Version(s)

gitoxide 0 < 0.37.1

gitoxide 0 < 0.58.1

gitoxide 0.37.1

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.