Libgit2 / Libgit2
22 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-53586 | libgit2: HTTP transport can leak credentials to an offsite redirect target | MEDIUM | 6.5 | Aug 20, 2026 |
| CVE-2026-53583 | libgit2: Inverted IP SubjectAltName Comparison in OpenSSL Backend | MEDIUM | 6.5 | Aug 20, 2026 |
| CVE-2026-53585 | libgit2: Unbounded Memory Allocation via Delta Object Result-Size Header | MEDIUM | 6.5 | Aug 20, 2026 |
| CVE-2026-53587 | libgit2 - Unauthenticated network-reachable heap out-of-bounds read in transports/smart_pkt.c:set_data | HIGH | 7.5 | Aug 20, 2026 |
| CVE-2026-53584 | libgit2: Submodule path traversal | MEDIUM | 4.3 | Aug 20, 2026 |
| CVE-2026-5917 | libgit2 Shell Command Injection via ssh_libssh2 Backend | HIGH | 8.6 | Aug 11, 2026 |
| CVE-2024-24577 | libgit2 is vulnerable to arbitrary code execution due to heap corruption in `git_index_add` | CRITICAL | 9.8 | Feb 6, 2024 |
| CVE-2024-24575 | libgit2 is vulnerable to a denial of service attack in `git_revparse_single` | HIGH | 7.5 | Feb 6, 2024 |
| CVE-2023-22742 | libgit2 fails to verify SSH keys by default | MEDIUM | 5.9 | Jan 20, 2023 |
| CVE-2020-12279 | libgit2: NTFS protections inactive when running Git in the Windows Subsystem for Linux | CRITICAL | 9.8 | Apr 27, 2020 |
| CVE-2020-12278 | libgit2: files inside the .git directory may be overwritten during cloning via NTFS Alternate Data Streams | CRITICAL | 9.8 | Apr 27, 2020 |
| CVE-2014-9390 | git: arbitrary command execution vulnerability on case-insensitive file systems | CRITICAL | 9.3 | Feb 12, 2020 |
| CVE-2018-15501 | libgit2: out-of-bounds reads when processing smart-protocol ng packets | HIGH | 7.5 | Aug 18, 2018 |
| CVE-2018-10888 | A flaw was found in libgit2 before version 0.27.3. A missing check in git_delta_apply function in delta.c file, may lead to an out-of-bound read while reading… | MEDIUM | 6.5 | Jul 10, 2018 |
| CVE-2018-10887 | A flaw was found in libgit2 before version 0.27.3. It has been discovered that an unexpected sign extension in git_delta_apply function in delta.c file may lea… | HIGH | 8.1 | Jul 10, 2018 |
| CVE-2018-8099 | libgit2: denial of service (DoS) via crafted repository index files | MEDIUM | 6.5 | Mar 14, 2018 |
| CVE-2018-8098 | libgit2: denial of service (DoS) via crafted repository index files | MEDIUM | 6.5 | Mar 14, 2018 |
| CVE-2016-10130 | The http_connect function in transports/http.c in libgit2 before 0.24.6 and 0.25.x before 0.25.1 might allow man-in-the-middle attackers to spoof servers by le… | MEDIUM | 5.9 | Mar 24, 2017 |
| CVE-2016-10129 | The Git Smart Protocol support in libgit2 before 0.24.6 and 0.25.x before 0.25.1 allows remote attackers to cause a denial of service (NULL pointer dereference… | HIGH | 7.5 | Mar 24, 2017 |
| CVE-2016-10128 | Buffer overflow in the git_pkt_parse_line function in transports/smart_pkt.c in the Git Smart Protocol support in libgit2 before 0.24.6 and 0.25.x before 0.25.… | CRITICAL | 9.8 | Mar 24, 2017 |
| CVE-2016-8569 | The git_oid_nfmt function in commit.c in libgit2 before 0.24.3 allows remote attackers to cause a denial of service (NULL pointer dereference) via a cat-file c… | MEDIUM | 5.5 | Feb 3, 2017 |
| CVE-2016-8568 | The git_commit_message function in oid.c in libgit2 before 0.24.3 allows remote attackers to cause a denial of service (out-of-bounds read) via a cat-file comm… | MEDIUM | 5.5 | Feb 3, 2017 |
Showing 1 to 22 of 22 CVEs