CVE-2026-53586

EUVD-2026-63550
libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality into your application. Prior to 1.8.6 and 1.9.5, the built-in HTTP transport in src/libgit2/transports/http.c follows an offsite initial redirect, and handle_remote_auth and handle_auth pass transport->owner->url instead of transport->server.url to the credential callback when the redirected host returns 401 Unauthorized. A callback that scopes credentials to the original trusted URL can therefore return GIT_CREDENTIAL_USERPASS_PLAINTEXT credentials that libgit2 stores in transport->server.cred and sends as an Authorization header to the redirected host. An attacker who controls a trusted Git host or an open redirect on that host can disclose HTTP Basic credentials, personal access tokens, or equivalent credentials. This issue is fixed in versions 1.8.6 and 1.9.5.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
GitHub_MCNA
6.5 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
libgit2libgit2
𝑥
< 1.8.6
CNA
Debian logo
Debian Releases
Debian Product
Codename
libgit2
bookworm
vulnerable
bookworm (security)
vulnerable
bullseye
vulnerable
bullseye (security)
vulnerable
forky
1.9.6+ds-1
fixed
sid
1.9.7+ds-1
fixed
trixie
no-dsa
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
libgit2
bionic
not-affected
focal
Fixed 0.28.4+dfsg.1-2ubuntu0.1+esm1
released
jammy
Fixed 1.1.0+dfsg.1-4.1ubuntu0.1+esm1
released
noble
Fixed 1.7.2+ds-1ubuntu3.1
released
resolute
Fixed 1.9.1+ds-1ubuntu1.1
released
trusty
not-affected
xenial
not-affected
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
cargo
Amazon Linux 2
0:1.97.0-2.amzn2
fixed
Amazon Linux 2023
0:1.97.0-2.amzn2023
fixed
cargo-debuginfo
Amazon Linux 2023
0:1.97.0-2.amzn2023
fixed
clippy
Amazon Linux 2
0:1.97.0-2.amzn2
fixed
Amazon Linux 2023
0:1.97.0-2.amzn2023
fixed
clippy-debuginfo
Amazon Linux 2023
0:1.97.0-2.amzn2023
fixed
rust
Amazon Linux 2
0:1.97.0-2.amzn2
fixed
Amazon Linux 2023
0:1.97.0-2.amzn2023
fixed
rust-analyzer
Amazon Linux 2
0:1.97.0-2.amzn2
fixed
Amazon Linux 2023
0:1.97.0-2.amzn2023
fixed
rust-analyzer-debuginfo
Amazon Linux 2023
0:1.97.0-2.amzn2023
fixed
rust-debugger-common
Amazon Linux 2
0:1.97.0-2.amzn2
fixed
Amazon Linux 2023
0:1.97.0-2.amzn2023
fixed
rust-debuginfo
Amazon Linux 2023
0:1.97.0-2.amzn2023
fixed
rust-debugsource
Amazon Linux 2023
0:1.97.0-2.amzn2023
fixed
rust-doc
Amazon Linux 2
0:1.97.0-2.amzn2
fixed
Amazon Linux 2023
0:1.97.0-2.amzn2023
fixed
rust-gdb
Amazon Linux 2
0:1.97.0-2.amzn2
fixed
Amazon Linux 2023
0:1.97.0-2.amzn2023
fixed
rust-lldb
Amazon Linux 2023
0:1.97.0-2.amzn2023
fixed
rust-src
Amazon Linux 2
0:1.97.0-2.amzn2
fixed
Amazon Linux 2023
0:1.97.0-2.amzn2023
fixed
rust-std-static
Amazon Linux 2
0:1.97.0-2.amzn2
fixed
Amazon Linux 2023
0:1.97.0-2.amzn2023
fixed
rust-std-static-wasm32-unknown-unknown
Amazon Linux 2023
0:1.97.0-2.amzn2023
fixed
rust-std-static-wasm32-wasip1
Amazon Linux 2023
0:1.97.0-2.amzn2023
fixed
rust-toolset
Amazon Linux 2
0:1.97.0-2.amzn2
fixed
Amazon Linux 2023
0:1.97.0-2.amzn2023
fixed
rust-toolset-srpm-macros
Amazon Linux 2
0:1.97.0-2.amzn2
fixed
Amazon Linux 2023
0:1.97.0-2.amzn2023
fixed
rustfmt
Amazon Linux 2
0:1.97.0-2.amzn2
fixed
Amazon Linux 2023
0:1.97.0-2.amzn2023
fixed
rustfmt-debuginfo
Amazon Linux 2023
0:1.97.0-2.amzn2023
fixed