Server Certificate Validation Flaw in libgit2 by GitHub
CVE-2026-53583
6.5MEDIUM
What is CVE-2026-53583?
A vulnerability in libgit2 prior to versions 1.8.6 and 1.9.5 allows a network attacker to intercept connections to IP-literal HTTPS URLs due to improper handling of certificate subject alternative names. The flawed function verify_server_cert incorrectly treats matching IP addresses during validation, making it possible for a malicious actor with a CA-trusted certificate containing an IP SubjectAltName to bypass security measures. Users are strongly encouraged to update to the latest versions to mitigate this risk.
Affected Version(s)
libgit2 < 1.8.6 < 1.8.6
libgit2 >= 1.9.0, < 1.9.5 < 1.9.0, 1.9.5
