Insufficiently Protected Credentials Affecting rust-gix-transport package, versions <0.57.0-1


Severity

Recommended
0.0
medium
0
10

Snyk's Security Team recommends NVD's CVSS assessment. Learn more

Threat Intelligence

EPSS
0.23% (15th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-DEBIAN14-RUSTGIXTRANSPORT-19428077
  • published29 Aug 2026
  • disclosed28 Aug 2026

Introduced: 28 Aug 2026

NewCVE-2026-82255  (opens in a new tab)
CWE-522  (opens in a new tab)

How to fix?

Upgrade Debian:14 rust-gix-transport to version 0.57.0-1 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream rust-gix-transport package and not the rust-gix-transport package as distributed by Debian. See How to fix? for Debian:14 relevant fixed versions and status.

gitoxide versions from 0.25.4 contain an HTTP credential leak vulnerability in the curl-based transport backend where credentials are sent to attacker-controlled servers after HTTP redirects. The vulnerability occurs because credential validation checks the original URL instead of the effective URL after redirect, allowing attackers to steal authentication tokens through cross-domain redirects or HTTPS-to-HTTP downgrades.

CVSS Base Scores

version 3.1