Description
libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality into your application. Prior to 1.8.6 and 1.9.5, the built-in HTTP transport in src/libgit2/transports/http.c follows an offsite initial redirect, and handle_remote_auth and handle_auth pass transport->owner->url instead of transport->server.url to the credential callback when the redirected host returns 401 Unauthorized. A callback that scopes credentials to the original trusted URL can therefore return GIT_CREDENTIAL_USERPASS_PLAINTEXT credentials that libgit2 stores in transport->server.cred and sends as an Authorization header to the redirected host. An attacker who controls a trusted Git host or an open redirect on that host can disclose HTTP Basic credentials, personal access tokens, or equivalent credentials. This issue is fixed in versions 1.8.6 and 1.9.5.
Published: 2026-08-20
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability arises when libgit2's HTTP transport follows an offsite initial redirect. During the redirect, the callback receives the original URL instead of the redirected host's URL. If the original URL is trusted, the callback may supply plain‑text credentials. libgit2 then stores those credentials and transmits them to the redirected host as an Authorization header. An attacker that controls the redirect target—or a trusted Git host that can issue an open redirect—therefore can retrieve HTTP Basic credentials, personal access tokens, or equivalent secrets. This leads to credential disclosure and violates confidentiality.

Affected Systems

The flaw is present in the libgit2 library itself. Any application that links against libgit2 before version 1.8.6 or 1.9.5 is vulnerable. The issue was fixed in those releases, so any software using libgit2 1.8.6 or newer, or 1.9.5 or newer, is no longer affected. Developers of custom Git tools or services that embed libgit2 should verify that their binaries use a patched version.

Risk and Exploitability

The CVSS base score is 6.5, reflecting moderate severity. The EPSS score of 0.00469 (~0.47%) suggests a low probability of exploitation, but the vulnerability can still be leveraged when an attacker can influence the HTTP redirect chain, such as by hosting a malicious Git service or exploiting an open redirect on a trusted host. The issue is not listed in CISA KEV, indicating that widespread exploitation has not yet been observed. Nonetheless, because the disclosure of credentials can lead to compromised accounts or systems, the risk should be considered significant, especially in environments where libgit2 is used to communicate with untrusted or potentially compromised hosts.

Generated by OpenCVE AI on August 24, 2026 at 13:57 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade libgit2 to version 1.8.6 or 1.9.5, which contains the fix.
  • If the library cannot be upgraded, patch or adjust the credential callback to reject credentials when the host changes during an HTTP redirect.
  • Validate redirect targets or disable automatic redirects within the application to prevent sending credentials to unintended hosts.

Generated by OpenCVE AI on August 24, 2026 at 13:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6453-1 libgit2 security update
History

Mon, 24 Aug 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-201
References
Metrics threat_severity

None

threat_severity

Moderate


Thu, 20 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Libgit2
Libgit2 libgit2
Vendors & Products Libgit2
Libgit2 libgit2

Thu, 20 Aug 2026 19:00:00 +0000

Type Values Removed Values Added
Description libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality into your application. Prior to 1.8.6 and 1.9.5, the built-in HTTP transport in src/libgit2/transports/http.c follows an offsite initial redirect, and handle_remote_auth and handle_auth pass transport->owner->url instead of transport->server.url to the credential callback when the redirected host returns 401 Unauthorized. A callback that scopes credentials to the original trusted URL can therefore return GIT_CREDENTIAL_USERPASS_PLAINTEXT credentials that libgit2 stores in transport->server.cred and sends as an Authorization header to the redirected host. An attacker who controls a trusted Git host or an open redirect on that host can disclose HTTP Basic credentials, personal access tokens, or equivalent credentials. This issue is fixed in versions 1.8.6 and 1.9.5.
Title libgit2: HTTP transport can leak credentials to an offsite redirect target
Weaknesses CWE-200
CWE-522
CWE-601
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-08-21T21:46:05.425Z

Reserved: 2026-06-09T19:11:53.484Z

Link: CVE-2026-53586

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-20T19:16:54.983

Modified: 2026-09-09T21:19:49.197

Link: CVE-2026-53586

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-08-20T18:40:08Z

Links: CVE-2026-53586 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-24T14:00:14Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-201

    Insertion of Sensitive Information Into Sent Data

  • CWE-522

    Insufficiently Protected Credentials

  • CWE-601

    URL Redirection to Untrusted Site ('Open Redirect')