Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-6453-1 | libgit2 security update |
Thu, 20 Aug 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Libgit2
Libgit2 libgit2 |
|
| Vendors & Products |
Libgit2
Libgit2 libgit2 |
Thu, 20 Aug 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 20 Aug 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality into your application. Prior to 1.8.6 and 1.9.5, verify_server_cert in src/libgit2/streams/openssl.c uses an inverted !!memcmp result in the GEN_IPADD branch when comparing an IP-literal host with a certificate IP SubjectAltName. OpenSSL builds reject matching IP addresses and accept mismatched IP addresses, allowing a network attacker with a CA-trusted certificate containing any IP SubjectAltName to intercept libgit2 connections to IP-literal HTTPS URLs. DNS SubjectAltName validation and non-OpenSSL TLS backends are not affected. This issue is fixed in versions 1.8.6 and 1.9.5. | |
| Title | libgit2: Inverted IP SubjectAltName Comparison in OpenSSL Backend | |
| Weaknesses | CWE-295 CWE-297 |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-08-20T19:04:42.247Z
Reserved: 2026-06-09T19:11:53.484Z
Link: CVE-2026-53583
Updated: 2026-08-20T19:02:30.259Z
Status : Received
Published: 2026-08-20T19:16:54.500
Modified: 2026-08-20T19:16:54.500
Link: CVE-2026-53583
No data.
OpenCVE Enrichment
Updated: 2026-08-20T20:30:05Z
Debian DSA