[Git][security-tracker-team/security-tracker][master] Add part of the new gix related CVEs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sat Aug 29 09:56:27 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
8d2d8587 by Salvatore Bonaccorso at 2026-08-29T10:51:52+02:00
Add part of the new gix related CVEs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -516,9 +516,11 @@ CVE-2026-82257 (SvelteKit versions before 2.69.1 contain a prototype pollution v
 CVE-2026-82256 (SvelteKit before 2.69.1 fails to properly validate remote form functio ...)
 	NOT-FOR-US: SvelteKit
 CVE-2026-82255 (gitoxide versions from 0.25.4 contain an HTTP credential leak vulnerab ...)
-	TODO: check
+	- rust-gix-transport 0.57.0-1
+	NOTE: https://github.com/GitoxideLabs/gitoxide/security/advisories/GHSA-9857-6mw7-fq2m
 CVE-2026-82254 (gitoxide before 0.69.0 contains unchecked array indexing in delta appl ...)
-	TODO: check
+	- rust-gix-pack 0.70.0-1
+	NOTE: https://github.com/GitoxideLabs/gitoxide/security/advisories/GHSA-x494-mj8g-cj27
 CVE-2026-82253 (gitoxide (Rust crates gix <= 0.72.0 and gix-validate <= 0.10.0) contai ...)
 	TODO: check
 CVE-2026-82252 (gitoxide before 0.52.1 follows symlinks when reading the worktree .git ...)
@@ -526,13 +528,16 @@ CVE-2026-82252 (gitoxide before 0.52.1 follows symlinks when reading the worktre
 CVE-2026-82251 (gitoxide before 0.52.1 fails to validate submodule names from .gitmodu ...)
 	TODO: check
 CVE-2026-82250 (gitoxide gix-packetline versions before 0.21.5 contain a panic vulnera ...)
-	TODO: check
+	- rust-gix-packetline 0.22.0-1
+	NOTE: https://github.com/GitoxideLabs/gitoxide/security/advisories/GHSA-2vh6-hw4j-32ww
 CVE-2026-82249 (gitoxide before 0.38.2 fails to validate carriage return characters in ...)
 	TODO: check
 CVE-2026-82248 (gix-worktree-state before 0.33.0 (part of gitoxide) allows writing fil ...)
 	TODO: check
 CVE-2026-82247 (gitoxide's gix-url crate (<= 0.32.0, fixed in 0.37.1) uses a hand-roll ...)
-	TODO: check
+	- rust-gix-url 0.37.1-1
+	- rust-gix-transport 0.58.1-1
+	NOTE: https://github.com/GitoxideLabs/gitoxide/security/advisories/GHSA-jrcm-326h-gpp8
 CVE-2026-82246 (Budibase Server before 3.41.3 contains a server-side request forgery v ...)
 	NOT-FOR-US: Budibase
 CVE-2026-82245 (Budibase before 3.41.3 fails to enforce role-based authorization on li ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8d2d85873b5b8da3168fb2c928c1e590597898c1

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8d2d85873b5b8da3168fb2c928c1e590597898c1
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260829/0a051797/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list