libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality into your application. Prior to 1.8.6 and 1.9.5, verify_server_cert in src/libgit2/streams/openssl.c uses an inverted !!memcmp result in the GEN_IPADD branch when comparing an IP-literal host with a certificate IP SubjectAltName. OpenSSL builds reject matching IP addresses and accept mismatched IP addresses, allowing a network attacker with a CA-trusted certificate containing any IP SubjectAltName to intercept libgit2 connections to IP-literal HTTPS URLs. DNS SubjectAltName validation and non-OpenSSL TLS backends are not affected. This issue is fixed in versions 1.8.6 and 1.9.5.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade libgit2 | Aug 21, 2026 | Aug 20, 2026 |
| Amazon_linux_2023 | — | Upgrade rustUpgrade rust-gdbUpgrade rust-analyzerUpgrade rust-toolsetUpgrade clippy-debuginfoUpgrade cargo-debuginfoUpgrade libgit2-develUpgrade rust-debugsourceUpgrade rust-std-static-wasm32-unknown-unknownUpgrade libgit2-debugsourceUpgrade rust-lldbUpgrade rust-debuginfoUpgrade libgit2Upgrade libgit2-debuginfoUpgrade rust-std-static-wasm32-wasip1Upgrade rust-std-staticUpgrade rust-debugger-commonUpgrade rust-analyzer-debuginfoUpgrade cargoUpgrade clippyUpgrade rustfmt-debuginfoUpgrade rust-srcUpgrade rust-docUpgrade rustfmtUpgrade rust-toolset-srpm-macros | Aug 21, 2026 | Aug 20, 2026 |
| Debian | — | Upgrade libgit2 | Aug 23, 2026 | Aug 23, 2026 |
| Redhat_linux | — | No solution exists | Aug 25, 2026 | Aug 20, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub