CVE-2025-31130

EUVD-2025-9751
gitoxide is an implementation of git written in Rust. Before 0.42.0, gitoxide uses SHA-1 hash implementations without any collision detection, leaving it vulnerable to hash collision attacks. gitoxide uses the sha1_smol or sha1 crate, both of which implement standard SHA-1 without any mitigations for collision attacks. This means that two distinct Git objects with colliding SHA-1 hashes would break the Git object model and integrity checks when used with gitoxide. This vulnerability is fixed in 0.42.0.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
GitHub_MCNA
6.8 MEDIUM
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 16.19%
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
gitoxidelabsgitoxide
𝑥
< 0.42.0
CNA
Debian logo
Debian Releases
Debian Product
Codename
rust-gix-features
forky
0.48.0-1
fixed
sid
0.49.0-1
fixed
trixie
0.39.1-2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
rust-gix-features
focal
dne
jammy
dne
noble
needs-triage
oracular
ignored
plucky
ignored
questing
ignored
resolute
needs-triage