CVE-2026-82250: gitoxide gix-packetline before 0.21.5 Denial of Service

Published Aug 28, 2026
·
Updated

gitoxide gix-packetline versions before 0.21.5 contain a panic vulnerability in the TextRef implementation that occurs when processing side-band packet lines with empty payloads. A malicious Git server can send a crafted side-band packet to trigger an index out of bounds panic, aborting the client process during fetch operations without authentication.

Affected Software

1 affected component
gitoxide/gix-packetline<0.21.5

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade gitoxide gix-packetline to a version that resolves this vulnerability.

    Fixed in 0.21.5
  2. Compensating control

    Mitigate the fetch-operation DoS risk by preventing untrusted or malicious Git servers from being contacted by clients (e.g., restrict allowed Git remote hosts via network controls/ACLs) until gix-packetline is upgraded to 0.21.5 or later.

Event History

Aug 28, 2026
CVE Published
via MITRE·10:49 AM
Data Sourced
via MITRE·10:49 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who is exposed to this denial of service?

Clients using gix-packetline before 0.21.5 are exposed when they perform fetch operations against a malicious Git server. Exploitation does not require authentication, but it requires the user or automated client to interact with the malicious server.

2

What is the practical impact of successful exploitation?

A crafted side-band packet line with an empty payload can cause an index-out-of-bounds panic in the TextRef implementation. This aborts the affected client process, resulting in a denial of service for the fetch operation.

3

What is the remediation?

Upgrade gix-packetline to version 0.21.5 or later. Until upgrading is possible, avoid fetching from untrusted or potentially malicious Git servers.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203