{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/gix-url--0.32.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:gitoxide:gix-url:*:*:*:*:*:*:*:*","cpe:2.3:a:gitoxide:gix-transport:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-82247"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["gix-url (\u003c= 0.32.0)","gix-transport (\u003c= 0.49.0)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["gitoxide"],"content_html":"\u003cp\u003eCVE-2026-82247 describes a security vulnerability in the gitoxide Rust crates gix-url (versions \u0026lt;= 0.32.0) and gix-transport (versions \u0026lt;= 0.49.0). The vulnerability stems from a custom URL parser in gix-url that fails to correctly interpret the '?' or '#' characters as terminators for the authority component of a URL, as defined in RFC 3986. This incorrect parsing allows the gix-transport HTTP redirect identity guard (can_reuse_identity) to misidentify the target host during an HTTP redirect.\u003c/p\u003e\n\u003cp\u003eAn attacker can exploit this by returning a malicious HTTP 3xx redirect with a crafted 'Location' header formatted as \u0026lt;attacker-authority\u0026gt;?@\u0026lt;original-authority\u0026gt;. The vulnerable identity guard incorrectly validates the target host, leading the client to reuse stored HTTP Basic Authorization credentials for the unintended attacker-controlled server. This flaw poses a high risk for any application leveraging gitoxide for Git operations that involve authenticating to remote repositories. Impacted users should update to gix-url 0.37.1 and gix-transport 0.58.1.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker hosts a malicious Git repository or HTTP server capable of serving custom HTTP 3xx redirect responses.\u003c/li\u003e\n\u003cli\u003eVictim initiates a Git operation (e.g., clone, fetch, or push) using a tool built with the vulnerable gitoxide crates.\u003c/li\u003e\n\u003cli\u003eVictim provides valid HTTP Basic Authorization credentials for the legitimate target repository.\u003c/li\u003e\n\u003cli\u003eAttacker returns an HTTP redirect response with a specially crafted 'Location' header: \u0026lt;attacker-authority\u0026gt;?@\u0026lt;original-authority\u0026gt;.\u003c/li\u003e\n\u003cli\u003eThe gix-url parser processes the 'Location' header but fails to terminate the authority component at the '?' character.\u003c/li\u003e\n\u003cli\u003eThe gix-transport identity guard compares the authority based on the flawed parsing and determines it is safe to reuse the existing credentials.\u003c/li\u003e\n\u003cli\u003eThe client library automatically includes the Authorization header containing the victim's credentials in the subsequent request to the attacker-controlled authority.\u003c/li\u003e\n\u003cli\u003eAttacker logs the Authorization header, successfully capturing the victim's plaintext credentials.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in the unauthorized exposure of HTTP Basic Authorization credentials to an attacker. This potentially grants the attacker persistent access to the victim's private repositories or associated services, depending on the scope of the captured credentials. This affects any downstream software in the Rust ecosystem that integrates the gitoxide library for repository interaction.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eIdentify all applications and internal tooling within the organization that utilize the gitoxide Rust crates by auditing Cargo.lock files for gix-url and gix-transport.\u003c/li\u003e\n\u003cli\u003eUpdate gix-url to version 0.37.1 or higher and gix-transport to version 0.58.1 or higher to incorporate the corrected URL parsing logic.\u003c/li\u003e\n\u003cli\u003eFor applications where immediate patching is not possible, implement strict allowlists for trusted host destinations to prevent redirects to unauthorized domains.\u003c/li\u003e\n\u003cli\u003ePerform log analysis on outbound HTTP requests from build servers and automated tooling to identify suspicious redirect responses involving unconventional URL formatting.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-08-28T15:13:19Z","date_published":"2026-08-28T15:13:19Z","id":"https://feed.craftedsignal.io/briefs/2026-08-gitoxide-url-parsing/","summary":"An improper URL parsing flaw in the gitoxide gix-url crate enables credential theft by causing the gix-transport identity guard to transmit HTTP Basic Authorization headers to unauthorized hosts via crafted redirects.","title":"Credential Disclosure Vulnerability in gitoxide gix-url and gix-transport Crates","url":"https://feed.craftedsignal.io/briefs/2026-08-gitoxide-url-parsing/"}],"language":"en","title":"CraftedSignal Threat Feed - Gix-Url (\u003c= 0.32.0)","version":"https://jsonfeed.org/version/1.1"}