rpm package
opensuse/stgit&distro=openSUSE Leap 16.0
pkg:rpm/opensuse/stgit&distro=openSUSE%20Leap%2016.0
Vulnerabilities (1)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-40034 | Hig | 7.8 | < 2.6.0-bp160.1.1 | 2.6.0-bp160.1.1 | May 26, 2026 | gix-submodule before 0.29.0 (gitoxide before 0.5.21, gix before 0.84.0) incorrectly validates the update field in .gitmodules, allowing attackers to bypass the CommandForbiddenInModulesConfiguration guard when a submodule has been initialized with only partial configuration in .g |
- affected < 2.6.0-bp160.1.1fixed 2.6.0-bp160.1.1
gix-submodule before 0.29.0 (gitoxide before 0.5.21, gix before 0.84.0) incorrectly validates the update field in .gitmodules, allowing attackers to bypass the CommandForbiddenInModulesConfiguration guard when a submodule has been initialized with only partial configuration in .g