CVE-2026-82250 HIGH

CVE-2026-82250: gitoxide gix-packetline before 0.21.5 Denial of Service

Vendor Gitoxidelabs
Product gitoxide
Weakness CWE-191
Published August 28, 2026
Last update August 28, 2026

CVSS base score

7.1/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

What the vulnerability does

01Description

gitoxide gix-packetline versions before 0.21.5 contain a panic vulnerability in the TextRef implementation that occurs when processing side-band packet lines with empty payloads. A malicious Git server can send a crafted side-band packet to trigger an index out of bounds panic, aborting the client process during fetch operations without authentication.

Key dates

02Disclosure timeline

August 28, 2026 CVE published
August 28, 2026 Record updated