云虫漏洞情报

CVE-2026-82249 - gitoxide before 0.38.2 fails to validate carriage return characters in URL values passed to credential helpers. Attackers can supply URLs containing bare carriage returns to inject additional helper protocol fields and cause credential helpers to return credentials for attacker-specified hosts instead of the requested URL. - 漏洞详情

漏洞编号:CVE-2026-82249

风险等级:低危

漏洞来源:CVE

CVE 编号:CVE-2026-82249

CNNVD 编号:-

厂商/产品:- / -

影响范围:-

CWE:CWE-116

发布/更新时间:2026-08-28 / 2026-08-28

漏洞描述

gitoxide before 0.38.2 fails to validate carriage return characters in URL values passed to credential helpers. Attackers can supply URLs containing bare carriage returns to inject additional helper protocol fields and cause credential helpers to return credentials for attacker-specified hosts instead of the requested URL.

相关链接

相关漏洞

« 返回首页