mediumVulnerability

GHSA-8rgq-m2pm-jvmg

### Duplicate Advisory This advisory has been withdrawn because it is a duplicate of GHSA-6mw6-mj76-grwc. This link is maintained to preserve external references. ### Original Description A flaw was found in gix-date. The `gix_date::parse::TimeBuf::as_str` function can generate strings containing invalid non-UTF8 characters. This issue violates the internal safety invariants of the `TimeBuf` component, leading to undefined behavior when these malformed strings are subsequently processed. This could potentially result in application instability or other unforeseen consequences.

Properties

ghsa_id
GHSA-8rgq-m2pm-jvmg
severity
medium
summary
Duplicate Advisory: gix-date can create non-utf8 string with `TimeBuf::as_str`
cve_id
GHSA-8rgq-m2pm-jvmg
is_ghsa_only
true
ghsa_published
2026-01-26T21:30:36Z
source_url
https://github.com/advisories/GHSA-8rgq-m2pm-jvmg
ghsa_updated
2026-01-27T22:22:40Z

Related Entities (3)

HAS_WEAKNESS (1)

[Weakness]Out-of-bounds Write

REPORTED_BY (1)

[Source]GitHub Advisory Database

AFFECTS (1)

[Software]rust/gix-date

Explore deeper with Ninja Signal's threat intelligence graph