CVE Vulnerabilities

CVE-2026-0810

Incorrect Calculation of Multi-Byte String Length

Published: Jan 26, 2026 | Modified: Feb 13, 2026
CVSS 3.x
7.1
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
6.8 MODERATE
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

A flaw was found in gix-date. The gix_date::parse::TimeBuf::as_str function can generate strings containing invalid non-UTF8 characters. This issue violates the internal safety invariants of the TimeBuf component, leading to undefined behavior when these malformed strings are subsequently processed. This could potentially result in application instability or other unforeseen consequences.

Weakness

The product does not correctly calculate the length of strings that can contain wide or multi-byte characters.

Affected Software

NameVendorStart VersionEnd Version
Gix-dateGitoxidelabs*0.12.0 (excluding)

Potential Mitigations

References