libgit2 released security fixes in versions 1.9.5 and 1.9.7 to address multiple vulnerabilities affecting HTTP authentication, smart packet parsing, submodule handling, TLS certificate validation, regex processing, delta handling, and SSH transport escaping. The most serious issues include CVE-2026-53587, a heap out-of-bounds read in smart_pkt.c triggered by malformed capability data, and CVE-2026-53584, a submodule path traversal flaw that could create directories outside a repository working tree. Other patched issues include CVE-2026-53586 for credential leakage across redirected HTTP hosts, CVE-2026-53585 for unbounded memory allocation that can cause denial of service, and CVE-2026-53583 for incorrect IP SubjectAltName verification in the OpenSSL backend that could enable man-in-the-middle attacks.
Project commits show the packet-parsing fix added explicit length checks before comparing the object-format= capability, preventing strncmp from reading past truncated packet data; equivalent patches were applied on the main, v1.9.7, and v1.8 maintenance lines. The 1.9.5 release also fixed a heap buffer overflow in bundled PCRE reachable through revspec parsing and an error-handling flaw in blame hunk creation, while 1.9.7 additionally addressed CVE-2026-5917, a libssh2 transport escaping issue that could lead to command injection. Users on the v1.8 branch were advised to move to 1.8.6 or 1.8.7, which are believed to contain corresponding fixes.

See affected versions and whether adversaries are exploiting it.
5 events from the most recent confirmed update back to the earliest known activity.
On July 18, 2026, libgit2 committed the smart packet parsing bounds-check fix to the main branch in commit d7a9fb8. The patch prevents reading past available packet data when checking for the object-format capability in set_data.
On July 18, 2026, libgit2 released version 1.9.5 as a security update fixing multiple vulnerabilities, including CVE-2026-53583, CVE-2026-53584, CVE-2026-53585, CVE-2026-53586, and CVE-2026-53587, plus a bundled PCRE issue. The release notes advised users to upgrade to the patched release.
On June 6, 2026, libgit2 committed the same smart packet parsing bounds check to the maint/v1.9 branch, adding a length guard before comparing the object-format capability string in src/libgit2/transports/smart_pkt.c. The fix is associated with the v1.9.7 maintenance line.
On June 6, 2026, libgit2 committed a bounds-checking fix on the maint/v1.8 branch to ensure packet data is long enough before checking the object-format capability in smart packet parsing. This change addresses the unsafe parsing condition later described as CVE-2026-53587 and is associated with v1.8.6/v1.8.7.
An oss-sec post reported that libgit2 versions 1.9.5 and 1.9.7 fix multiple security vulnerabilities across HTTP authentication, regex parsing, packet parsing, submodule path handling, TLS certificate validation, delta processing, and SSH path escaping. It highlighted CVE-2026-53587 and CVE-2026-53584 as especially significant and advised users of the v1.8 line to upgrade.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
5 references tracked. Mallory keeps watching after this page renders.
seclists.org
Open sourcegithub.com
Open sourcegithub.com
Open sourcegithub.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.