DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CGA-vrch-vmjm-3288

Package

helix

Component

gix-packetline

Latest update

Pending upstream fix

Aliases

Severity

6.5

Medium

CVSS V3

Eliminate CVEs with Chainguard hardened images

Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.

Start for free

References

  • https://github.com/advisories/GHSA-2vh6-hw4j-32ww

Updates

Status

Pending upstream fix

Impact

GHSA-2vh6-hw4j-32ww affects the bundled gix-packetline crate (reachable panic on an empty side-band packet during a network fetch). The fix is only in gix-packetline 0.21.5 and later, which belongs to the gix 0.85 release train. helix 25.07.1 pins gix to the 0.72.x range (gix-packetline 0.19.0), so cargo cannot resolve the patched version; the automated bump in stereo PR #282290 fails to compile because gix 0.85 changes the gix EntryStatus API used by helix-vcs. Upstream moved to gix 0.85.0 on the development branch (helix-editor/helix PR #15959, 2026-07-03) but no tagged release since 25.07.1 contains it. Pending an upstream helix release adopting gix 0.85 or newer.

Status

Under investigation


The trusted source for open source

Talk to an expert
PrivacyTerms

Product

Chainguard ContainersChainguard LibrariesChainguard VMsChainguard OS PackagesChainguard ActionsChainguard Agent SkillsIntegrationsPricing
© 2026 Chainguard, Inc. All Rights Reserved.
Chainguard® and the Chainguard logo are registered trademarks of Chainguard, Inc. in the United States and/or other countries.
The other respective trademarks mentioned on this page are owned by the respective companies and use of them does not imply any affiliation or endorsement.