HIGHcrates.io →
gitoxide does not detect SHA-1 collision attacks
gitoxide does not detect SHA-1 collision attacks
Affected packages
- gitoxide
- gitoxide-core
- gix
- gix-archive
- gix-blame
- gix-commitgraph
- gix-config
- gix-diff
- gix-dir
- gix-discover
- gix-features
- gix-filter
- gix-fsck
- gix-index
- gix-merge
- gix-negotiate
- gix-object
- gix-odb
- gix-pack
- gix-protocol
- gix-ref
- gix-revision
- gix-revwalk
- gix-status
- gix-traverse
- gix-worktree
- gix-worktree-state
Exploit signal
- Known exploited (CISA KEV)
- No
- EPSS score
- —
- EPSS percentile
- —
EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs.
Sources
- https://github.com/GitoxideLabs/gitoxide/security/advisories/GHSA-2frx-2596-x5r6
- https://nvd.nist.gov/vuln/detail/CVE-2025-31130
- https://github.com/GitoxideLabs/gitoxide/commit/f253f02a6658b3b7612a50d56c71f5ae4da4ca21
- https://github.com/GitoxideLabs/gitoxide
- https://rustsec.org/advisories/RUSTSEC-2025-0021.html
Structured record: https://osv.dev/vulnerability/GHSA-2frx-2596-x5r6
Recommended response stack
Some links are affiliate links — HackTribune may earn a commission at no extra cost to you.
Get incidents like this as alerts for your stack.
Join the beta