CVE-2026-53583
EUVD-2026-6354920.08.2026, 19:16
libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality into your application. Prior to 1.8.6 and 1.9.5, verify_server_cert in src/libgit2/streams/openssl.c uses an inverted !!memcmp result in the GEN_IPADD branch when comparing an IP-literal host with a certificate IP SubjectAltName. OpenSSL builds reject matching IP addresses and accept mismatched IP addresses, allowing a network attacker with a CA-trusted certificate containing any IP SubjectAltName to intercept libgit2 connections to IP-literal HTTPS URLs. DNS SubjectAltName validation and non-OpenSSL TLS backends are not affected. This issue is fixed in versions 1.8.6 and 1.9.5.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| libgit2 | libgit2 | 𝑥 < 1.8.6 | CNA |
Debian Releases
Ubuntu Releases
Amazon Linux Releases
Amazon Package | |||||
|---|---|---|---|---|---|
| cargo |
| ||||
| cargo-debuginfo |
| ||||
| clippy |
| ||||
| clippy-debuginfo |
| ||||
| rust |
| ||||
| rust-analyzer |
| ||||
| rust-analyzer-debuginfo |
| ||||
| rust-debugger-common |
| ||||
| rust-debuginfo |
| ||||
| rust-debugsource |
| ||||
| rust-doc |
| ||||
| rust-gdb |
| ||||
| rust-lldb |
| ||||
| rust-src |
| ||||
| rust-std-static |
| ||||
| rust-std-static-wasm32-unknown-unknown |
| ||||
| rust-std-static-wasm32-wasip1 |
| ||||
| rust-toolset |
| ||||
| rust-toolset-srpm-macros |
| ||||
| rustfmt |
| ||||
| rustfmt-debuginfo |
|
Common Weakness Enumeration
References