Server Certificate Validation Flaw in libgit2 by GitHub
CVE-2026-53583

6.5MEDIUM

Key Information:

Vendor

Libgit2

Status
Vendor
CVE Published:
20 August 2026

What is CVE-2026-53583?

A vulnerability in libgit2 prior to versions 1.8.6 and 1.9.5 allows a network attacker to intercept connections to IP-literal HTTPS URLs due to improper handling of certificate subject alternative names. The flawed function verify_server_cert incorrectly treats matching IP addresses during validation, making it possible for a malicious actor with a CA-trusted certificate containing an IP SubjectAltName to bypass security measures. Users are strongly encouraged to update to the latest versions to mitigate this risk.

Affected Version(s)

libgit2 < 1.8.6 < 1.8.6

libgit2 >= 1.9.0, < 1.9.5 < 1.9.0, 1.9.5

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.