{"id":"GHSA-8rgq-m2pm-jvmg","summary":"Duplicate Advisory: gix-date can create non-utf8 string with `TimeBuf::as_str`","details":"### Duplicate Advisory\n\nThis advisory has been withdrawn because it is a duplicate of GHSA-6mw6-mj76-grwc. This link is maintained to preserve external references.\n\n### Original Description\nA flaw was found in gix-date. The `gix_date::parse::TimeBuf::as_str` function can generate strings containing invalid non-UTF8 characters. This issue violates the internal safety invariants of the `TimeBuf` component, leading to undefined behavior when these malformed strings are subsequently processed. This could potentially result in application instability or other unforeseen consequences.","modified":"2026-02-03T03:07:15.414323Z","published":"2026-01-26T21:30:36Z","withdrawn":"2026-01-27T22:22:39Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2026-01-27T22:22:39Z","nvd_published_at":"2026-01-26T20:16:09Z","severity":"MODERATE","cwe_ids":["CWE-787"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-0810"},{"type":"WEB","url":"https://github.com/GitoxideLabs/gitoxide/issues/2305"},{"type":"WEB","url":"https://access.redhat.com/security/cve/CVE-2026-0810"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2427057"},{"type":"WEB","url":"https://crates.io/crates/gix-date"},{"type":"PACKAGE","url":"https://github.com/GitoxideLabs/gitoxide"},{"type":"WEB","url":"https://rustsec.org/advisories/RUSTSEC-2025-0140.html"}],"affected":[{"package":{"name":"gix-date","ecosystem":"crates.io","purl":"pkg:cargo/gix-date"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.12.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/01/GHSA-8rgq-m2pm-jvmg/GHSA-8rgq-m2pm-jvmg.json"}}],"schema_version":"1.7.3","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:P"}]}