Vulnerability record · CVE-2026-0810 · published 26 January 2026
CVE-2026-0810: Gitoxidelabs gix-date vulnerability
GGitoxidelabs · Gix Date
A flaw was found in gix-date. The `gix_date::parse::TimeBuf::as_str` function can generate strings containing invalid non-UTF8 characters. This issue violates the internal safety invariants of the `TimeBuf` component, leading to undefined behavior when these malformed strings are subsequently processed. This could potentially result in application instability or other unforeseen consequences.
Description
A flaw was found in gix-date. The `gix_date::parse::TimeBuf::as_str` function can generate strings containing invalid non-UTF8 characters. This issue violates the internal safety invariants of the `TimeBuf` component, leading to undefined behavior when these malformed strings are subsequently processed. This could potentially result in application instability or other unforeseen consequences.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://access.redhat.com/security/cve/CVE-2026-0810 | Third Party Advisory |
| https://bugzilla.redhat.com/show_bug.cgi?id=2427057 | Issue Tracking |
| https://crates.io/crates/gix-date | Product |
| https://github.com/GitoxideLabs/gitoxide/issues/2305 | ExploitIssue Tracking |
| https://rustsec.org/advisories/RUSTSEC-2025-0140.html | Third Party Advisory |
| https://github.com/GitoxideLabs/gitoxide/issues/2305 | ExploitIssue Tracking |
Track CVE-2026-0810 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Source: NIST National Vulnerability Database (record CVE-2026-0810), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.