Control Character Injection in gitoxide gix-transport by Gitoxide
CVE-2026-91986

5.3MEDIUM

Key Information:

Status
Vendor
CVE Published:
15 September 2026

What is CVE-2026-91986?

The gitoxide gix-transport product prior to version 0.59.2 is susceptible to a control character injection vulnerability. This issue occurs when the software fails to properly filter control characters within git-daemon connect requests. An attacker could exploit this flaw by crafting malicious git URLs that contain NUL, CR, or LF bytes, enabling them to inject unnecessary NUL-delimited protocol fields. Such an attack could allow adversaries to spoof virtual hosts or insert newlines into daemon requests and logs, potentially leading to further security breaches and data integrity issues.

Affected Version(s)

gitoxide 0 < 0.59.2

gitoxide 0.59.2

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

manus-use
.