PT-2026-83107 · Gitoxide · Gitoxide

·

CVE-2026-82255

·

Published

2026-08-28

·

Updated

2026-08-28

CVSS v4.0

7.6

High

VectorAV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions gitoxide versions 0.25.4 and later
Description An issue exists in the curl-based transport backend where credentials may be leaked to attacker-controlled servers following HTTP redirects. This occurs because the credential validation process verifies the original URL rather than the effective URL after the redirect has taken place. Consequently, attackers can steal authentication tokens by utilizing cross-domain redirects or HTTPS-to-HTTP downgrades.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Insufficiently Protected Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-82255

Affected Products

Gitoxide