CVE-2026-53583

EUVD-2026-63549
libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality into your application. Prior to 1.8.6 and 1.9.5, verify_server_cert in src/libgit2/streams/openssl.c uses an inverted !!memcmp result in the GEN_IPADD branch when comparing an IP-literal host with a certificate IP SubjectAltName. OpenSSL builds reject matching IP addresses and accept mismatched IP addresses, allowing a network attacker with a CA-trusted certificate containing any IP SubjectAltName to intercept libgit2 connections to IP-literal HTTPS URLs. DNS SubjectAltName validation and non-OpenSSL TLS backends are not affected. This issue is fixed in versions 1.8.6 and 1.9.5.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
GitHub_MCNA
6.5 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
libgit2libgit2
𝑥
< 1.8.6
CNA
Debian logo
Debian Releases
Debian Product
Codename
libgit2
bookworm
vulnerable
bookworm (security)
vulnerable
bullseye
vulnerable
bullseye (security)
vulnerable
forky
1.9.6+ds-1
fixed
sid
1.9.7+ds-1
fixed
trixie
no-dsa
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
libgit2
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
needs-triage
resolute
needs-triage
trusty
needs-triage
xenial
needs-triage
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
cargo
Amazon Linux 2
0:1.97.0-2.amzn2
fixed
Amazon Linux 2023
0:1.97.0-2.amzn2023
fixed
cargo-debuginfo
Amazon Linux 2023
0:1.97.0-2.amzn2023
fixed
clippy
Amazon Linux 2
0:1.97.0-2.amzn2
fixed
Amazon Linux 2023
0:1.97.0-2.amzn2023
fixed
clippy-debuginfo
Amazon Linux 2023
0:1.97.0-2.amzn2023
fixed
rust
Amazon Linux 2
0:1.97.0-2.amzn2
fixed
Amazon Linux 2023
0:1.97.0-2.amzn2023
fixed
rust-analyzer
Amazon Linux 2
0:1.97.0-2.amzn2
fixed
Amazon Linux 2023
0:1.97.0-2.amzn2023
fixed
rust-analyzer-debuginfo
Amazon Linux 2023
0:1.97.0-2.amzn2023
fixed
rust-debugger-common
Amazon Linux 2
0:1.97.0-2.amzn2
fixed
Amazon Linux 2023
0:1.97.0-2.amzn2023
fixed
rust-debuginfo
Amazon Linux 2023
0:1.97.0-2.amzn2023
fixed
rust-debugsource
Amazon Linux 2023
0:1.97.0-2.amzn2023
fixed
rust-doc
Amazon Linux 2
0:1.97.0-2.amzn2
fixed
Amazon Linux 2023
0:1.97.0-2.amzn2023
fixed
rust-gdb
Amazon Linux 2
0:1.97.0-2.amzn2
fixed
Amazon Linux 2023
0:1.97.0-2.amzn2023
fixed
rust-lldb
Amazon Linux 2023
0:1.97.0-2.amzn2023
fixed
rust-src
Amazon Linux 2
0:1.97.0-2.amzn2
fixed
Amazon Linux 2023
0:1.97.0-2.amzn2023
fixed
rust-std-static
Amazon Linux 2
0:1.97.0-2.amzn2
fixed
Amazon Linux 2023
0:1.97.0-2.amzn2023
fixed
rust-std-static-wasm32-unknown-unknown
Amazon Linux 2023
0:1.97.0-2.amzn2023
fixed
rust-std-static-wasm32-wasip1
Amazon Linux 2023
0:1.97.0-2.amzn2023
fixed
rust-toolset
Amazon Linux 2
0:1.97.0-2.amzn2
fixed
Amazon Linux 2023
0:1.97.0-2.amzn2023
fixed
rust-toolset-srpm-macros
Amazon Linux 2
0:1.97.0-2.amzn2
fixed
Amazon Linux 2023
0:1.97.0-2.amzn2023
fixed
rustfmt
Amazon Linux 2
0:1.97.0-2.amzn2
fixed
Amazon Linux 2023
0:1.97.0-2.amzn2023
fixed
rustfmt-debuginfo
Amazon Linux 2023
0:1.97.0-2.amzn2023
fixed