<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-09T22:02:33.947111+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-cx7h-h87r-jpgr</id>
    <title>GHSA-cx7h-h87r-jpgr — The kstring integration in gix-attributes is unsound</title>
    <updated>2026-10-09T22:02:33.948263+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> crates.io: gix-attributes</p>
<p>`gix-attributes` (in [`state::ValueRef`](https://github.com/Byron/gitoxide/blob/gix-attributes-v0.22.2/gix-attributes/src/state.rs#L19-L27)) unsafely creates a `&amp;str` from a `&amp;[u8]` containing non-UTF8 data, with the justification that so long as nothing reads the `&amp;str` and relies on it being UTF-8 in the `&amp;str`, there is no UB:</p>
<p>```rust
// SAFETY: our API makes accessing that value as `str` impossible, so illformed UTF8 is never exposed as such.
```</p>
<p>The problem is that the non-UTF8 `str` **is** exposed to outside code: first to the `kstring` crate itself, which requires UTF-8 in its documentation and may have UB as a consequence of this, but also to `serde`, where it propagates to e.g. `serde_json`, `serde_yaml`, etc., where the same problems occur.</p>
<p>This is not sound, and it could cause further UB down the line in these places that can view the `&amp;str`.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-cx7h-h87r-jpgr"/>
  </entry>
</feed>
