Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2748▲ 38 respecto a la semana anterior
Críticas / altas1479▲ 369 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
24 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.3) | 0.15% | — | Gitoxidelabs Gix-fsAI | 25/9/2026 | 28/9/2026 | gitoxide gix-fs before 0.23.0 contains a path validation bypass vulnerability in the worktree checkout mechanism that allows attackers to escape the worktree directory via symlink manipulation. During forced checkout with overwrite_existing enabled, attackers can craft malicious repository trees where symlink entries… | |
| Aplazada | Media (5.3) | 0.23% | — | Gitoxide Gix-transportAI | 15/9/2026 | 23/9/2026 | gitoxide gix-transport before 0.59.2 fails to filter control characters in git-daemon connect requests, allowing attackers to inject NUL/CR/LF bytes via crafted git URLs. Attackers can inject extra NUL-delimited protocol fields to spoof virtual hosts or inject newlines into daemon requests and logs. | |
| Aplazada | Media (6.8) | 0.19% | — | GitoxideAIGitoxide Gix-secAI | 14/9/2026 | 23/9/2026 | gitoxide is an implementation of git written in Rust. Prior to 0.13.3, the gix-sec crate on Windows incorrectly treats repositories controlled by another user as trusted when an administrator runs a dependent program with an unfiltered elevated token. In gix-sec/src/identity.rs,… | |
| Aplazada | Alta (8.7) | 0.49% | — | GitoxideAI | 28/8/2026 | 28/8/2026 | gitoxide before 0.69.0 contains unchecked array indexing in delta application and uncapped allocation from attacker-controlled size headers in gix-pack. Attackers can send crafted pack data during clone or fetch operations to trigger panics or out-of-memory process kills. | |
| Aplazada | Alta (8.7) | 0.66% | — | Gitoxide GIXAIGitoxide Gix-validateAI | 28/8/2026 | 31/8/2026 | gitoxide (Rust crates gix <= 0.72.0 and gix-validate <= 0.10.0) contains a path traversal vulnerability. The submodule name validation function in gix-validate only checks the first occurrence of '..' via name.find(b".."), allowing crafted names such as 'a..b/../../../.git/' to bypass the check; additionally this… | |
| Aplazada | Alta (8.7) | 0.52% | — | GitoxideAI | 28/8/2026 | 29/8/2026 | gitoxide before 0.52.1 follows symlinks when reading the worktree .gitmodules file, allowing attackers to inject out-of-repository bytes into submodule metadata. Attackers can create a malicious repository with a symlinked .gitmodules pointing outside the repository tree, causing gitoxide to parse arbitrary external… | |
| Aplazada | Alta (8.7) | 0.52% | — | GitoxideAI | 28/8/2026 | 29/8/2026 | gitoxide before 0.52.1 fails to validate submodule names from .gitmodules configuration, allowing path traversal when deriving submodule git directories. Attackers can craft malicious submodule names with traversal segments to redirect state() and open() functions to repositories outside .git/modules, causing… | |
| Aplazada | Alta (7.1) | 0.43% | — | Gitoxide Gix-packetlineAI | 28/8/2026 | 28/8/2026 | gitoxide gix-packetline versions before 0.21.5 contain a panic vulnerability in the TextRef implementation that occurs when processing side-band packet lines with empty payloads. A malicious Git server can send a crafted side-band packet to trigger an index out of bounds panic, aborting the client process during fetch… | |
| Aplazada | Baja (2.3) | 0.27% | — | GitoxideAI | 28/8/2026 | 28/8/2026 | gitoxide before 0.38.2 fails to validate carriage return characters in URL values passed to credential helpers. Attackers can supply URLs containing bare carriage returns to inject additional helper protocol fields and cause credential helpers to return credentials for attacker-specified hosts instead of the requested… | |
| Aplazada | Media (6) | 0.34% | — | Gitoxide GIX Worktree StateAI | 28/8/2026 | 31/8/2026 | gix-worktree-state before 0.33.0 (part of gitoxide) allows writing files outside the worktree on Windows. gix_worktree_state::checkout() follows an existing terminal symlink during non-exclusive (incremental) materialization (destination_is_initially_empty: false) when core.symlinks is true. If a symlink entry (mode… | |
| Aplazada | Alta (8.7) | 0.41% | — | Gitoxide Gix-urlAIGitoxide Gix-transportAI | 28/8/2026 | 28/8/2026 | gitoxide's gix-url crate (<= 0.32.0, fixed in 0.37.1) uses a hand-rolled URL parser that does not treat '?' or '#' as terminating the authority component, contrary to RFC 3986. As a consequence, gix-transport's HTTP redirect identity guard (can_reuse_identity) compares the wrong host and fails open. An attacker… | |
| Aplazada | Alta (7.6) | 0.38% | — | GitoxideAI | 28/8/2026 | 30/9/2026 | gitoxide versions from 0.25.4 contain an HTTP credential leak vulnerability in the curl-based transport backend where credentials are sent to attacker-controlled servers after HTTP redirects. The vulnerability occurs because credential validation checks the original URL instead of the effective URL after redirect,… | |
| Aplazada | Alta (8.5) | 0.36% | — | GitoxideAIGIXAIGIX SubmoduleAI | 26/5/2026 | 24/7/2026 | gix-submodule before 0.29.0 (gitoxide before 0.5.21, gix before 0.84.0) incorrectly validates the update field in .gitmodules, allowing attackers to bypass the CommandForbiddenInModulesConfiguration guard when a submodule has been initialized with only partial configuration in .git/config. An attacker can inject… | |
| Analizada | Alta (7.8) | 0.21% | — | Gitoxidelabs Gix-fs | 13/5/2026 | 17/6/2026 | gitoxide is an implementation of git written in Rust. Prior to 0.21.1, a malicious tree can be constructed that will, when checked out with gitoxide, permit writing an attacker-controlled symlink into any existing directory the user has write access to. During checkout, all symlink index entries are deferred and… | |
| Modificada | Alta (7.1) | 0.21% | — | Gitoxidelabs Gix-date | 26/1/2026 | 17/6/2026 | A flaw was found in gix-date. The `gix_date::parse::TimeBuf::as_str` function can generate strings containing invalid non-UTF8 characters. This issue violates the internal safety invariants of the `TimeBuf` component, leading to undefined behavior when these malformed strings are subsequently processed. This could… | |
| Aplazada | Media (6.8) | 0.25% | — | GitoxideAISha1 SmolAISha1AI | 4/4/2025 | 17/6/2026 | gitoxide is an implementation of git written in Rust. Before 0.42.0, gitoxide uses SHA-1 hash implementations without any collision detection, leaving it vulnerable to hash collision attacks. gitoxide uses the sha1_smol or sha1 crate, both of which implement standard SHA-1 without any mitigations for collision… | |
| Aplazada | Media (5) | 0.37% | — | GitoxideAI | 20/1/2025 | 17/6/2026 | gitoxide is an implementation of git written in Rust. Prior to 0.17.0, gix-worktree-state specifies 0777 permissions when checking out executable files, intending that the umask will restrict them appropriately. But one of the strategies it uses to set permissions is not subject to the umask. This causes files in a… | |
| Aplazada | Media (6) | 0.26% | — | Gitoxide Gix-pathAI | 6/9/2024 | 17/6/2026 | `gix-path` is a crate of the `gitoxide` project (an implementation of `git` written in Rust) dealing paths and their conversions. Prior to version 0.10.11, `gix-path` runs `git` to find the path of a configuration file associated with the `git` installation, but improperly resolves paths containing unusual or… | |
| Aplazada | Baja (2.5) | 0.24% | — | Gitoxide Gix-pathAI | 2/9/2024 | 17/6/2026 | gix-path is a crate of the gitoxide project dealing with git paths and their conversions. `gix-path` executes `git` to find the path of a configuration file that belongs to the `git` installation itself, but mistakenly treats the local repository's configuration as system-wide if no higher scoped configuration is… | |
| Aplazada | Baja (2.5) | 0.20% | — | GitoxideAI | 22/8/2024 | 17/6/2026 | gitoxide An idiomatic, lean, fast & safe pure Rust implementation of Git. gitoxide-core, which provides most underlying functionality of the gix and ein commands, does not neutralize newlines, backspaces, or control characters—including those that form ANSI escape sequences—that appear in a repository's paths, author… | |
| Aplazada | Media (6.8) | 0.21% | — | Gitoxide Gix-pathAI | 18/7/2024 | 17/6/2026 | gitoxide An idiomatic, lean, fast & safe pure Rust implementation of Git. `gix-path` can be tricked into running another `git.exe` placed in an untrusted location by a limited user account on Windows systems. Windows permits limited user accounts without administrative privileges to create new directories in the root… | |
| Aplazada | Media (5.4) | 0.45% | — | GitoxideAI | 23/5/2024 | 17/6/2026 | gitoxide is a pure Rust implementation of Git. On Windows, fetching refs that clash with legacy device names reads from the devices, and checking out paths that clash with such names writes arbitrary data to the devices. This allows a repository, when cloned, to cause indefinite blocking or the production of arbitrary… | |
| Aplazada | Alta (8.8) | 0.82% | — | GitoxideAI | 23/5/2024 | 17/6/2026 | gitoxide is a pure Rust implementation of Git. During checkout, `gix-worktree-state` does not verify that paths point to locations in the working tree. A specially crafted repository can, when cloned, place new files anywhere writable by the application. This vulnerability leads to a major loss of confidentiality,… | |
| Aplazada | Media (6.4) | 0.51% | — | Gitoxide Gix-transportAI | 26/4/2024 | 17/6/2026 | gitoxide is a pure Rust implementation of Git. `gix-transport` does not check the username part of a URL for text that the external `ssh` program would interpret as an option. A specially crafted clone URL can smuggle options to SSH. The possibilities are syntactically limited, but if a malicious clone URL is used by… |