CVE-2026-0810CWE-135

Gix-date: gix-date: undefined behavior due to invalid string generation

High · published January 26, 2026

CVSS v3.1
7.1
EPSS
0%
Percentile
9.4
In the wild
Unconfirmed
What it is

A flaw was found in gix-date. The `gix_date::parse::TimeBuf::as_str` function can generate strings containing invalid non-UTF8 characters. This issue violates the internal safety invariants of the `TimeBuf` component, leading to undefined behavior when these malformed strings are subsequently processed. This could potentially result in application instability or other unforeseen consequences.

The record
Technical detail
CVSS v3.1
7.1 · HIGH
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
CVSS v4.0
Not supplied
EPSS
0.00196 · 9.4th percentile
Weakness
CWE-135 · Incorrect Calculation of Multi-Byte String Length
Published
2026-01-26T19:36Z
EPSS history
Timeline
  • 26 JAN 19:36Z
    Gix-date: gix-date: undefined behavior due to invalid string generation
    cvelistv5