Control Character Injection in gitoxide gix-transport by Gitoxide
CVE-2026-91986
5.3MEDIUM
What is CVE-2026-91986?
The gitoxide gix-transport product prior to version 0.59.2 is susceptible to a control character injection vulnerability. This issue occurs when the software fails to properly filter control characters within git-daemon connect requests. An attacker could exploit this flaw by crafting malicious git URLs that contain NUL, CR, or LF bytes, enabling them to inject unnecessary NUL-delimited protocol fields. Such an attack could allow adversaries to spoof virtual hosts or insert newlines into daemon requests and logs, potentially leading to further security breaches and data integrity issues.
Affected Version(s)
gitoxide 0 < 0.59.2
gitoxide 0.59.2
