{"id":"AZL-98433","summary":"CVE-2026-82253 affecting package rust 1.90.0-10","details":"gitoxide (Rust crates gix \u003c= 0.72.0 and gix-validate \u003c= 0.10.0) contains a path traversal vulnerability. The submodule name validation function in gix-validate only checks the first occurrence of '..' via name.find(b\"..\"), allowing crafted names such as 'a..b/../../../.git/' to bypass the check; additionally this validation is never invoked in production code paths. Combined with a trust inheritance flaw in Submodule::open(), where the parent repository's git_dir_trust (Trust::Full) is cloned and the ownership verification is skipped, an attacker can craft a malicious .gitmodules file so that a victim tool built on gitoxide reads arbitrary git repository configuration (including embedded credentials) with full trust, bypassing safe-directory protections. Fixed in gix 0.82.0 and gix-validate 0.11.1.","modified":"2026-09-04T05:27:10Z","published":"2026-08-28T12:16:38Z","upstream":["CVE-2026-82253"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-82253"}],"affected":[{"package":{"name":"rust","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/rust"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.85.0"},{"last_affected":"1.90.0-10"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-98433.json"}}],"schema_version":"1.9.0"}