CVE-2026-0810

HIGH EPSS 9.2%
Published Jan 26, 20265mo ago · Modified Jun 17, 20261w ago
7.1 CVSS 3.1
High
Find Similar
Published Jan 26, 2026 5mo ago
Last Modified Jun 17, 2026 1w ago

Description

A flaw was found in gix-date. The `gix_date::parse::TimeBuf::as_str` function can generate strings containing invalid non-UTF8 characters. This issue violates the internal safety invariants of the `TimeBuf` component, leading to undefined behavior when these malformed strings are subsequently processed. This could potentially result in application instability or other unforeseen consequences.

CVSS Details

Base Score
7.1
Exploitability
1.8
Impact
5.2
Vector string
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Attack Vector Local
Attack Complexity Low
Privileges Required Low
User Interaction None
Scope Unchanged
Confidentiality None
Integrity High
Availability High

Threat Intelligence

EPSS Exploit Probability
9.2% percentile
Exploit & Patch Status
Public Exploit Known
No Patch Available

Weaknesses 2

CWE-135
CWE-682

Affected Products 1

VendorProductVersionRange
gitoxidelabsgix-date* <0.12.0

References 5

  • access.redhat.com https://access.redhat.com/security/cve/CVE-2026-0810
    Third Party Advisory
  • bugzilla.redhat.com https://bugzilla.redhat.com/show_bug.cgi?id=2427057
    Issue Tracking
  • crates.io https://crates.io/crates/gix-date
    Product
  • github.com https://github.com/GitoxideLabs/gitoxide/issues/2305
    ExploitIssue Tracking
  • rustsec.org https://rustsec.org/advisories/RUSTSEC-2025-0140.html
    Third Party Advisory

Remediation

No remediation data recorded yet

Check vendor advisories and the NVD entry for patch availability.