<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T20:49:42.844828+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-266439</id>
    <title>EUVD-2026-266439</title>
    <updated>2026-10-04T20:49:42.849081+00:00</updated>
    <content>EUVD-2026-266439</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-266439"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-31130</id>
    <title>fkie_cve-2025-31130</title>
    <updated>2026-10-04T20:49:42.849113+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>gitoxide is an implementation of git written in Rust. Before 0.42.0, gitoxide uses SHA-1 hash implementations without any collision detection, leaving it vulnerable to hash collision attacks. gitoxide uses the sha1_smol or sha1 crate, both of which implement standard SHA-1 without any mitigations for collision attacks. This means that two distinct Git objects with colliding SHA-1 hashes would break the Git object model and integrity checks when used with gitoxide. This vulnerability is fixed in 0.42.0.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-31130"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-2frx-2596-x5r6</id>
    <title>GHSA-2frx-2596-x5r6 — gitoxide does not detect SHA-1 collision attacks</title>
    <updated>2026-10-04T20:49:42.849144+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> crates.io: gix-features, crates.io: gix-commitgraph, crates.io: gix-index, crates.io: gix-object, crates.io: gix-odb, crates.io: gix-pack, crates.io: gitoxide, crates.io: gitoxide-core, crates.io: gix, crates.io: gix-archive and 17 more</p>
<p>### Summary
gitoxide uses SHA-1 hash implementations without any collision detection, leaving it vulnerable to hash collision attacks.</p>
<p>### Details
gitoxide uses the `sha1_smol` or `sha1` crate, both of which implement standard SHA-1 without any mitigations for collision attacks. This means that two distinct Git objects with colliding SHA-1 hashes would break the Git object model and integrity checks when used with gitoxide.</p>
<p>The SHA-1 function is considered cryptographically insecure. However, in the wake of the SHAttered attacks, this issue was mitigated in Git 2.13.0 in 2017 by using the [sha1collisiondetection](https://github.com/crmarcstevens/sha1collisiondetection) algorithm by default and producing an error when known SHA-1 collisions are detected. Git is in the process of migrating to using SHA-256 for object hashes, but this has not been rolled out widely yet and gitoxide does not support SHA-256 object hashes.</p>
<p>### PoC
The following program demonstrates the problem, using the two [SHAttered PDFs](https://shattered.io/):</p>
<p>```rust
use sha1_checked::{CollisionResult, Digest};</p>
<p>fn sha1_oid_of_file(filename: &amp;str) -&gt; gix::ObjectId {
    let mut hasher = gix::features::hash::hasher(gix::hash::Kind::Sha1);
    hasher.update(&amp;std::fs::read(filename).unwrap());
    gix::ObjectId::Sha1(hasher.digest())
}</p>
<p>fn sha1dc_oid_of_file(filename: &amp;str) -&gt; Result&lt;gix::ObjectId, String&gt; {
    // Matches Git’s behaviour.
    let mut hasher = sha1_checked::Builder::default().safe_hash(fal…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-2frx-2596-x5r6"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2025:14994-1</id>
    <title>openSUSE-SU-2025:14994-1 — gitoxide-0.42.0-1.1 on GA media</title>
    <updated>2026-10-04T20:49:42.849221+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>gitoxide-0.42.0-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2025:14994-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rustsec-2025-0021</id>
    <title>RUSTSEC-2025-0021 — SHA-1 collision attacks are not detected</title>
    <updated>2026-10-04T20:49:42.849240+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> crates.io: gix-features</p>
<p>### Summary
gitoxide uses SHA-1 hash implementations without any collision detection, leaving it vulnerable to hash collision attacks.</p>
<p>### Details
gitoxide uses the `sha1_smol` or `sha1` crate, both of which implement standard SHA-1 without any mitigations for collision attacks. This means that two distinct Git objects with colliding SHA-1 hashes would break the Git object model and integrity checks when used with gitoxide.</p>
<p>The SHA-1 function is considered cryptographically insecure. However, in the wake of the SHAttered attacks, this issue was mitigated in Git 2.13.0 in 2017 by using the [sha1collisiondetection](https://github.com/crmarcstevens/sha1collisiondetection) algorithm by default and producing an error when known SHA-1 collisions are detected. Git is in the process of migrating to using SHA-256 for object hashes, but this has not been rolled out widely yet and gitoxide does not support SHA-256 object hashes.</p>
<p>### PoC
The following program demonstrates the problem, using the two [SHAttered PDFs](https://shattered.io/):</p>
<p>```rust
use sha1_checked::{CollisionResult, Digest};</p>
<p>fn sha1_oid_of_file(filename: &amp;str) -&gt; gix::ObjectId {
    let mut hasher = gix::features::hash::hasher(gix::hash::Kind::Sha1);
    hasher.update(&amp;std::fs::read(filename).unwrap());
    gix::ObjectId::Sha1(hasher.digest())
}</p>
<p>fn sha1dc_oid_of_file(filename: &amp;str) -&gt; Result&lt;gix::ObjectId, String&gt; {
    // Matches Git’s behaviour.
    let mut hasher = sha1_checked::Builder::default().safe_hash(fal…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rustsec-2025-0021"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-31130</id>
    <title>UBUNTU-CVE-2025-31130</title>
    <updated>2026-10-04T20:49:42.849284+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:24.04:LTS: rust-gix-features, Ubuntu:25.10: rust-gix-features, Ubuntu:26.04:LTS: rust-gix-features</p>
<p>gitoxide is an implementation of git written in Rust. Before 0.42.0, gitoxide uses SHA-1 hash implementations without any collision detection, leaving it vulnerable to hash collision attacks. gitoxide uses the sha1_smol or sha1 crate, both of which implement standard SHA-1 without any mitigations for collision attacks. This means that two distinct Git objects with colliding SHA-1 hashes would break the Git object model and integrity checks when used with gitoxide. This vulnerability is fixed in 0.42.0.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-31130"/>
  </entry>
</feed>
