U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2025-31130

Change History

CVE Modified by CISA-ADP 4/04/2025 11:15:48 AM

Action Type Old Value New Value
Added Reference

								
							
							
						
https://github.com/GitoxideLabs/gitoxide/security/advisories/GHSA-2frx-2596-x5r6

New CVE Received from GitHub, Inc. 4/04/2025 11:15:48 AM

Action Type Old Value New Value
Added Description

								
							
							
						
gitoxide is an implementation of git written in Rust. Before 0.42.0, gitoxide uses SHA-1 hash implementations without any collision detection, leaving it vulnerable to hash collision attacks. gitoxide uses the sha1_smol or sha1 crate, both of which implement standard SHA-1 without any mitigations for collision attacks. This means that two distinct Git objects with colliding SHA-1 hashes would break the Git object model and integrity checks when used with gitoxide. This vulnerability is fixed in 0.42.0.
Added CVSS V3.1

								
							
							
						
AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N
Added CWE

								
							
							
						
CWE-328
Added Reference

								
							
							
						
https://github.com/GitoxideLabs/gitoxide/commit/4660f7a6f71873311f68f170b0f1f6659a02829d
Added Reference

								
							
							
						
https://github.com/GitoxideLabs/gitoxide/security/advisories/GHSA-2frx-2596-x5r6