CVE-2026-82249

Publication date 31 August 2026

Last updated 31 August 2026


Ubuntu priority

Cvss 3 Severity Score

3.1 · Low

Score breakdown

Description

gitoxide before 0.38.2 fails to validate carriage return characters in URL values passed to credential helpers. Attackers can supply URLs containing bare carriage returns to inject additional helper protocol fields and cause credential helpers to return credentials for attacker-specified hosts instead of the requested URL.

Status

Package Ubuntu Release Status
rust-gix-credentials 26.04 LTS resolute
Needs evaluation
24.04 LTS noble
Needs evaluation
22.04 LTS jammy Not in release

Severity score breakdown

CVSS version:

Base score 2.3 · Low

Vector: CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

Base score 3.1 · Low

Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N


Access our resources on patching vulnerabilities