A vulnerability was detected in klaussilveira GitList 2.0.0. Affected by this issue is the function SimpleXMLElement of the file src/SCM/System/Git/CommandLine.php of the component XML Parsing. Performing a manipulation results in denial of service. The attack is possible to be carried out remotely. The exploit is now public and may be used. Upgrading to version 3.0.0-beta can resolve this issue. The patch is named f67609d52c1812fa8a7ed80eae5e795cfd72115f. It is advisable to upgrade the affected component.
CVE-2026-82669
Score 5.3 from GitHub Security Advisory published 2026-08-31. a secondary CVSS source baseline 5.3; sources differ by 0.0.
- Lower severity and no public exploit yet
No vendor fix yet — apply a workaround or compensating control (WAF / firewall / segmentation) and watch for a patch.
- CVSS v3
- 5.3
- EG Score
- 5.3(high)
- EG Risk
- 55(Attend)EG Risk 55/100SSVC: Attend
EG Risk is EchelonGraph's 0–100 priority score: it fuses intrinsic severity with real-world exploitation and automatability so you can rank equal-severity CVEs and fix the most dangerous first. Higher = act sooner. Distinct from the 0–10 EG Score (severity).
How it’s computedSeverity53% × 45%Exploitation40% × 40%Automatability100% × 15%Action: Remediate soon — notable exploitation risk. - EPSS PROB
- 0%
- EPSS %ILE
- 37%
- KEV
- Not listed
Published
August 31, 2026
Last Modified
September 2, 2026
Advisory Details (4)
Auto-updated Aug 31, 2026GitHub - klaussilveira/gitlist: An elegant and modern git repository viewer · GitHub
https://github.com/klaussilveira/gitlist/3.0.0-beta
Patch available: klaussilveira/gitlist 3.0.0-beta (pre-release)
https://github.com/klaussilveira/gitlist/releases/tag/3.0.0-betacommit f67609d52c18 (klaussilveira/gitlist)
Patch available: klaussilveira/gitlist 3.0.0-beta (contains commit f67609d52c18)
https://github.com/klaussilveira/gitlist/commit/f67609d52c1812fa8a7ed80eae5e795cfd72115fUnescaped Git Commit Metadata Triggers XML Parsing Failure and HTTP 500 · Issue #948 · klaussilveira/gitlist · GitHub
https://github.com/klaussilveira/gitlist/issues/948Vendor Advisories for CVE-2026-82669(1)
These vendors published their own advisory mentioning this CVE — often with vendor-specific remediation steps + affected product lists not in NVD.
Weakness Classification(1)
MITRE Common Weakness Enumeration — the root-cause categories this CVE belongs to.
Data Freshness Timeline
(refreshed 17× in last 7d / 61× in last 30d)
Each row is a source pipeline that fetched or updated this CVE on that date, with what changed. For example, "NVD update" means NVD published or revised its analysis for this CVE; "MITRE cvelistV5" means we ingested or refreshed it from the CNA feed. Most recent first.
- 2026-09-19 10:52 UTCEG score recompute
- 2026-09-19 10:52 UTCGHSA enrichment
- 2026-09-18 19:28 UTCEPSS rescore
- 2026-09-18 12:27 UTCEG score recompute
- 2026-09-18 12:27 UTCGHSA enrichment
- 2026-09-17 14:03 UTCGHSA enrichment
- 2026-09-16 15:38 UTCEG score recompute
- 2026-09-16 15:38 UTCGHSA enrichment
- 2026-09-16 14:08 UTCEPSS rescore
- 2026-09-16 05:15 UTCEPSS rescore
- 2026-09-15 17:05 UTCEG score recompute
- 2026-09-15 17:05 UTCGHSA enrichment
- 2026-09-15 03:12 UTCEPSS rescore
- 2026-09-15 03:12 UTCEPSS rescore
- 2026-09-14 18:41 UTCGHSA enrichment
- 2026-09-13 20:07 UTCEG score recompute
- 2026-09-13 20:07 UTCGHSA enrichment
- 2026-09-12 21:43 UTCEG score recompute
- 2026-09-12 21:43 UTCGHSA enrichment
- 2026-09-11 23:18 UTCEG score recompute
- 2026-09-11 23:18 UTCGHSA enrichment
- 2026-09-11 14:53 UTCEPSS rescore
- 2026-09-11 14:53 UTCEPSS rescore
- 2026-09-11 00:27 UTCEG score recompute
- 2026-09-11 00:27 UTCGHSA enrichment
Show 36 moreShow fewer
- 2026-09-10 02:02 UTCGHSA enrichment
- 2026-09-09 03:38 UTCEG score recompute
- 2026-09-09 03:37 UTCGHSA enrichment
- 2026-09-08 22:01 UTCEPSS rescore
- 2026-09-08 05:13 UTCEG score recompute
- 2026-09-08 05:12 UTCGHSA enrichment
- 2026-09-07 06:44 UTCEG score recompute
- 2026-09-07 06:44 UTCGHSA enrichment
- 2026-09-06 13:48 UTCEPSS rescore
- 2026-09-06 08:19 UTCEG score recompute
- 2026-09-06 08:18 UTCGHSA enrichment
- 2026-09-05 15:31 UTCEPSS rescore
- 2026-09-05 09:53 UTCEG score recompute
- 2026-09-05 09:53 UTCGHSA enrichment
- 2026-09-04 11:29 UTCEG score recompute
- 2026-09-04 11:29 UTCGHSA enrichment
- 2026-09-04 05:07 UTCEPSS rescore
- 2026-09-03 13:05 UTCGHSA enrichment
- 2026-09-02 14:34 UTCEG score recompute
- 2026-09-02 14:33 UTCGHSA enrichment
- 2026-09-02 14:22 UTCNVD updateCVSS v4 → 5.5
- 2026-09-02 14:12 UTCEPSS rescore
- 2026-09-02 13:52 UTCEG score recompute
- 2026-09-02 13:52 UTCGHSA enrichment
- 2026-09-02 13:48 UTCMITRE cvelistV5CVSS v4 → 6.9
- 2026-09-01 19:35 UTCEG score recompute
- 2026-09-01 19:35 UTCGHSA enrichment
- 2026-09-01 13:54 UTCEPSS rescore
- 2026-09-01 04:40 UTCEPSS rescore
- 2026-09-01 04:40 UTCEPSS rescore
- 2026-08-31 21:02 UTCEG score recompute
- 2026-08-31 21:02 UTCGHSA enrichment
- 2026-08-31 10:18 UTCEG score recompute
- 2026-08-31 10:17 UTCNVD updateCVSS v4 → 5.5
- 2026-08-31 09:38 UTCEG score recompute
- 2026-08-31 09:37 UTCMITRE cvelistV5first tracked
Related CVEs(same CWE)
Same CWE
10 shownCWE-404
- CVE-2018-8639NVD 7.8EG 9.0 KEVEPSS p98CRITICAL
- CVE-2018-8611NVD 7.8EG 9.0 KEVEPSS p90CRITICAL
- CVE-2018-8453NVD 7.8EG 9.0 KEVEPSS p99CRITICAL
- CVE-2018-8406NVD 7.8EG 9.0 KEVCRITICAL
- CVE-2018-8405NVD 7.8EG 9.0 KEVCRITICAL
- CVE-2018-8120NVD 7.0EG 9.0 KEVEPSS p99CRITICAL
- CVE-2017-6627NVD 7.5EG 9.0 KEVEPSS p93CRITICAL
- CVE-2018-8450EG 8.8EPSS p97HIGH
- CVE-2019-1708EG 8.6HIGH
- CVE-2019-1706EG 8.6HIGH
Frequently asked(5)
What is CVE-2026-82669?
When was CVE-2026-82669 disclosed?
Is CVE-2026-82669 actively exploited?
What is the CVSS score of CVE-2026-82669?
How do I remediate CVE-2026-82669?
Dependency Blast Radius
Explore the affected products and dependency analysis for CVE-2026-82669
Is Your Infrastructure Affected by CVE-2026-82669?
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.