Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2683▼ 54 respecto a la semana anterior
Críticas / altas1442▲ 305 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
–

36 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.3)0.15%—Gitoxidelabs Gix-fsAI25/9/202628/9/2026
gitoxide gix-fs before 0.23.0 contains a path validation bypass vulnerability in the worktree checkout mechanism that allows attackers to escape the worktree directory via symlink manipulation. During forced checkout with overwrite_existing enabled, attackers can craft malicious repository trees where symlink entries…
AplazadaMedia (5.3)0.23%—Gitoxide Gix-transportAI15/9/202623/9/2026
gitoxide gix-transport before 0.59.2 fails to filter control characters in git-daemon connect requests, allowing attackers to inject NUL/CR/LF bytes via crafted git URLs. Attackers can inject extra NUL-delimited protocol fields to spoof virtual hosts or inject newlines into daemon requests and logs.
AplazadaMedia (6.8)0.19%—GitoxideAIGitoxide Gix-secAI14/9/202623/9/2026
gitoxide is an implementation of git written in Rust. Prior to 0.13.3, the gix-sec crate on Windows incorrectly treats repositories controlled by another user as trusted when an administrator runs a dependent program with an unfiltered elevated token. In gix-sec/src/identity.rs,…
AplazadaAlta (8.7)0.49%—GitoxideAI28/8/202628/8/2026
gitoxide before 0.69.0 contains unchecked array indexing in delta application and uncapped allocation from attacker-controlled size headers in gix-pack. Attackers can send crafted pack data during clone or fetch operations to trigger panics or out-of-memory process kills.
AplazadaAlta (8.7)0.66%—Gitoxide GIXAIGitoxide Gix-validateAI28/8/202631/8/2026
gitoxide (Rust crates gix <= 0.72.0 and gix-validate <= 0.10.0) contains a path traversal vulnerability. The submodule name validation function in gix-validate only checks the first occurrence of '..' via name.find(b".."), allowing crafted names such as 'a..b/../../../.git/' to bypass the check; additionally this…
AplazadaAlta (8.7)0.52%—GitoxideAI28/8/202629/8/2026
gitoxide before 0.52.1 follows symlinks when reading the worktree .gitmodules file, allowing attackers to inject out-of-repository bytes into submodule metadata. Attackers can create a malicious repository with a symlinked .gitmodules pointing outside the repository tree, causing gitoxide to parse arbitrary external…
AplazadaAlta (8.7)0.52%—GitoxideAI28/8/202629/8/2026
gitoxide before 0.52.1 fails to validate submodule names from .gitmodules configuration, allowing path traversal when deriving submodule git directories. Attackers can craft malicious submodule names with traversal segments to redirect state() and open() functions to repositories outside .git/modules, causing…
AplazadaAlta (7.1)0.43%—Gitoxide Gix-packetlineAI28/8/202628/8/2026
gitoxide gix-packetline versions before 0.21.5 contain a panic vulnerability in the TextRef implementation that occurs when processing side-band packet lines with empty payloads. A malicious Git server can send a crafted side-band packet to trigger an index out of bounds panic, aborting the client process during fetch…
AplazadaBaja (2.3)0.27%—GitoxideAI28/8/202628/8/2026
gitoxide before 0.38.2 fails to validate carriage return characters in URL values passed to credential helpers. Attackers can supply URLs containing bare carriage returns to inject additional helper protocol fields and cause credential helpers to return credentials for attacker-specified hosts instead of the requested…
AplazadaMedia (6)0.34%—Gitoxide GIX Worktree StateAI28/8/202631/8/2026
gix-worktree-state before 0.33.0 (part of gitoxide) allows writing files outside the worktree on Windows. gix_worktree_state::checkout() follows an existing terminal symlink during non-exclusive (incremental) materialization (destination_is_initially_empty: false) when core.symlinks is true. If a symlink entry (mode…
AplazadaAlta (8.7)0.41%—Gitoxide Gix-urlAIGitoxide Gix-transportAI28/8/202628/8/2026
gitoxide's gix-url crate (<= 0.32.0, fixed in 0.37.1) uses a hand-rolled URL parser that does not treat '?' or '#' as terminating the authority component, contrary to RFC 3986. As a consequence, gix-transport's HTTP redirect identity guard (can_reuse_identity) compares the wrong host and fails open. An attacker…
AplazadaAlta (7.6)0.38%—GitoxideAI28/8/202630/9/2026
gitoxide versions from 0.25.4 contain an HTTP credential leak vulnerability in the curl-based transport backend where credentials are sent to attacker-controlled servers after HTTP redirects. The vulnerability occurs because credential validation checks the original URL instead of the effective URL after redirect,…
AplazadaAlta (7.3)0.17%—Jxl-oxide Jxl-gridAI19/8/202618/9/2026
jxl-oxide is a pure Rust implementation of a JPEG XL decoder. Prior to jxl-grid 0.6.2, decoding a crafted JPEG XL image on a 32-bit platform can overflow length calculations in AlignedGrid::with_alloc_tracker and related grid and subgrid arithmetic. A 65536 x 65536 frame can pass the frame-area limit while overflowing…
AplazadaAlta (8.5)0.36%—GitoxideAIGIXAIGIX SubmoduleAI26/5/202624/7/2026
gix-submodule before 0.29.0 (gitoxide before 0.5.21, gix before 0.84.0) incorrectly validates the update field in .gitmodules, allowing attackers to bypass the CommandForbiddenInModulesConfiguration guard when a submodule has been initialized with only partial configuration in .git/config. An attacker can inject…
AnalizadaAlta (7.8)0.21%—Gitoxidelabs Gix-fs13/5/202617/6/2026
gitoxide is an implementation of git written in Rust. Prior to 0.21.1, a malicious tree can be constructed that will, when checked out with gitoxide, permit writing an attacker-controlled symlink into any existing directory the user has write access to. During checkout, all symlink index entries are deferred and…
ModificadaAlta (7.1)0.21%—Gitoxidelabs Gix-date26/1/202617/6/2026
A flaw was found in gix-date. The `gix_date::parse::TimeBuf::as_str` function can generate strings containing invalid non-UTF8 characters. This issue violates the internal safety invariants of the `TimeBuf` component, leading to undefined behavior when these malformed strings are subsequently processed. This could…
AplazadaMedia (5)0.22%—Oxide Control PlaneAI30/11/202517/6/2026
In Oxide control plane 15 through 17 before 17.1, API tokens can be renewed past their expiration date.
AplazadaMedia (6.8)0.25%—GitoxideAISha1 SmolAISha1AI4/4/202517/6/2026
gitoxide is an implementation of git written in Rust. Before 0.42.0, gitoxide uses SHA-1 hash implementations without any collision detection, leaving it vulnerable to hash collision attacks. gitoxide uses the sha1_smol or sha1 crate, both of which implement standard SHA-1 without any mitigations for collision…
AplazadaMedia (5)0.37%—GitoxideAI20/1/202517/6/2026
gitoxide is an implementation of git written in Rust. Prior to 0.17.0, gix-worktree-state specifies 0777 permissions when checking out executable files, intending that the umask will restrict them appropriately. But one of the strategies it uses to set permissions is not subject to the umask. This causes files in a…
AplazadaMedia (5.7)0.13%—OxideAI9/12/202417/6/2026
Oxide before 6 has unencrypted Control Plane datastores.
AplazadaCrítica (9.1)0.36%—Oxide Control PlaneAI5/12/202417/6/2026
Oxide control plane software before 5 allows SSRF.
AplazadaMedia (6)0.26%—Gitoxide Gix-pathAI6/9/202417/6/2026
`gix-path` is a crate of the `gitoxide` project (an implementation of `git` written in Rust) dealing paths and their conversions. Prior to version 0.10.11, `gix-path` runs `git` to find the path of a configuration file associated with the `git` installation, but improperly resolves paths containing unusual or…
AplazadaBaja (2.5)0.24%—Gitoxide Gix-pathAI2/9/202417/6/2026
gix-path is a crate of the gitoxide project dealing with git paths and their conversions. `gix-path` executes `git` to find the path of a configuration file that belongs to the `git` installation itself, but mistakenly treats the local repository's configuration as system-wide if no higher scoped configuration is…
AplazadaBaja (2.5)0.20%—GitoxideAI22/8/202417/6/2026
gitoxide An idiomatic, lean, fast & safe pure Rust implementation of Git. gitoxide-core, which provides most underlying functionality of the gix and ein commands, does not neutralize newlines, backspaces, or control characters—including those that form ANSI escape sequences—that appear in a repository's paths, author…
AplazadaMedia (6.8)0.21%—Gitoxide Gix-pathAI18/7/202417/6/2026
gitoxide An idiomatic, lean, fast & safe pure Rust implementation of Git. `gix-path` can be tricked into running another `git.exe` placed in an untrusted location by a limited user account on Windows systems. Windows permits limited user accounts without administrative privileges to create new directories in the root…