Known vulnerabilities in libgit2 (Ubuntu package)
Vendor:
Canonical Ltd.
Software:
libgit2 (Ubuntu package)
Software CPE:
cpe:2.3:o:canonical:libgit2_ubuntu_package:*:*:*:*:*:ubuntu:*:*
Website:
https://www.ubuntu.com/
Total vulnerabilities:
11
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
0.24.1-2ubuntu0.2+esm4
0.26.0+dfsg.1-1.1ubuntu0.2+esm3
0.28.4+dfsg.1-2ubuntu0.1+esm2
1.1.0+dfsg.1-4.1ubuntu0.1+esm2
1.7.2+ds-1ubuntu3.2
1.9.1+ds-1ubuntu1.2
1.9.0+ds-2ubuntu2
1.9.1+ds-1
1.9.1+ds-1ubuntu1
1.9.2+ds-1
1.9.2+ds-2
1.9.2+ds-3
1.9.2+ds-4
1.9.2+ds-5
1.9.2+ds-6
1.9.2+ds-7
1.9.2+ds-8
1.9.2+ds-9
1.9.3+ds-1
1.9.3+ds-1ubuntu1
1.9.3+ds-1ubuntu2
0.19.0-2ubuntu0.4+esm2
0.24.1-2ubuntu0.2+esm3
0.26.0+dfsg.1-1.1ubuntu0.2+esm2
0.28.4+dfsg.1-2ubuntu0.1+esm1
1.1.0+dfsg.1-4.1ubuntu0.1+esm1
1.7.2+ds-1ubuntu3.1
1.9.1+ds-1ubuntu1.1
1.5.0+ds-6ubuntu1
1.1.0+dfsg.1-4.1ubuntu0.1
1.1.0+dfsg.1-4.1build1
0.28.4+dfsg.1-2ubuntu0.1
0.28.3+dfsg.1-1ubuntu1
0.28.3+dfsg.1-1build1
1.9.0~ds-0ubuntu1
1.9.0+ds-2
1.9.0+ds-2ubuntu1
1.9.0+ds-1
1.9.0+ds-1ubuntu1
1.8.4+ds-3ubuntu2
1.8.4+ds-2
1.8.4+ds-3
1.8.4+ds-3ubuntu1
1.8.4+ds-1ubuntu1
1.8.4+ds-1
1.8.2~rc1+ds2-1ubuntu2
1.8.2~rc1+ds2-1ubuntu1
1.8.1+ds-1
1.8.1+ds-2
1.8.2~rc1+ds-1
1.8.2~rc1+ds-2
1.8.2~rc1+ds2-1
1.7.2+ds-1ubuntu3
1.7.2+ds-1ubuntu2
1.7.2+ds-1ubuntu1
1.7.2+ds-1
1.7.1+ds-2ubuntu1
1.6.4+ds-1
1.7.1+ds-1
1.7.1+ds-2
0.28.1+dfsg.1-0.1
0.28.3+dfsg.1-0.1
0.28.3+dfsg.1-1
0.28.4+dfsg.1-1
0.28.4+dfsg.1-3
0.28.4+dfsg.1-4
0.99.0+dfsg.1-1
1.0.0+dfsg.1-1
1.0.0+dfsg.1-2
1.0.1+dfsg.1-1
1.0.1+dfsg.1-3
1.1.0+dfsg.1-1
1.1.0+dfsg.1-2
1.1.0+dfsg.1-3
1.1.0+dfsg.1-4
1.1.0+dfsg.1-4.1
1.3.0+dfsg.1-1
1.3.0+dfsg.1-2
1.3.0+dfsg.1-3
1.3.0+dfsg.1-3ubuntu1
1.3.2+dfsg.1-0ubuntu1
1.4.3+dfsg.1-1
1.5.0+ds-1
1.5.0+ds-2
1.5.0+ds-3
1.5.0+ds-4
1.5.0+ds-5
1.5.0+ds-6
1.5.0+ds-6ubuntu2
1.5.1+ds-1
1.5.1+ds-1ubuntu1
1.5.1+ds-1ubuntu1.1
0.28.5+dfsg.1
0.28.5+dfsg.1-1
0.28.4+dfsg.1
0.28.4+dfsg.1-2
0.27.7+dfsg.1
0.27.7+dfsg.1-0.2build1
0.26.0+dfsg.1
0.24.1
0.19.0
0.27.7+dfsg.1-0.2
0.27.4+dfsg.1-0.1build1
0.26.0+dfsg.1-1.1ubuntu0.2
0.26.0+dfsg.1-1.1build1
0.24.1-2ubuntu0.2
0.27.0+dfsg.1-0.1
0.27.0+dfsg.1-0.2
0.27.0+dfsg.1-0.3
0.27.0+dfsg.1-0.4
0.27.0+dfsg.1-0.5
0.27.0+dfsg.1-0.6
0.27.0+dfsg.1-0.7
0.27.0+dfsg.1-0.8
0.27.0+dfsg.1-0.9
0.27.4+dfsg.1-0.1
0.27.7+dfsg.1-0.1
0.26.0+dfsg.1-1
0.26.0+dfsg.1-1.1
0.26.0+dfsg.1-1.2
0.26.0+dfsg.1-1.2build1
0.25.1+really0.24.6-1
0.19.0-2ubuntu0.4
0.25.1-1
0.25.1-2
0.24.5-1
0.24.2-1
0.24.2-2
0.23.1-1.1
0.24.0-1
0.24.0-2
0.24.1-1
0.24.1-2
0.23.1-1
0.22.2-1
0.22.2-2
0.22.1-0ubuntu3
0.22.1-0ubuntu2
0.22.1-0ubuntu1
0.16.0-1
0.17.0-1
0.18.0-1
0.18.0-2
0.19.0-1
0.19.0-2
0.20.0-1
0.21.0-1
0.21.1-1
0.21.2-1
0.21.2-2
0.21.3-1
0.21.3-1.1
Vulnerabilities (11)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU143594 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') CVE-2026-5917 |
CWE-78 | High | 0.24.1-2ubuntu0.2+esm4, 0.26.0+dfsg.1-1.1ubuntu0.2+esm3, 0.28.4+dfsg.1-2ubuntu0.1+esm2, 1.1.0+dfsg.1-4.1ubuntu0.1+esm2, 1.7.2+ds-1ubuntu3.2, 1.9.1+ds-1ubuntu1.2 | 16.08.2026 |
SB20260816530 SB2026081711 SB2026081712 and 9 more |
||
| #VU138490 - Insufficiently Protected Credentials CVE-2026-53586 |
CWE-522 | Medium | 0.19.0-2ubuntu0.4+esm2, 0.24.1-2ubuntu0.2+esm3, 0.26.0+dfsg.1-1.1ubuntu0.2+esm2, 0.28.4+dfsg.1-2ubuntu0.1+esm1, 1.1.0+dfsg.1-4.1ubuntu0.1+esm1, 1.7.2+ds-1ubuntu3.1, 1.9.1+ds-1ubuntu1.1 | 20.07.2026 |
SB2026072079 SB2026072444 SB2026072445 and 10 more |
||
| #VU138489 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CVE-2026-53584 |
CWE-22 | Low | 0.19.0-2ubuntu0.4+esm2, 0.24.1-2ubuntu0.2+esm3, 0.26.0+dfsg.1-1.1ubuntu0.2+esm2, 0.28.4+dfsg.1-2ubuntu0.1+esm1, 1.1.0+dfsg.1-4.1ubuntu0.1+esm1, 1.7.2+ds-1ubuntu3.1, 1.9.1+ds-1ubuntu1.1 | 20.07.2026 |
SB2026072079 SB2026072444 SB2026072445 and 10 more |
||
| #VU138487 - Out-of-bounds read CVE-2026-53587 |
CWE-125 | Medium | 0.19.0-2ubuntu0.4+esm2, 0.24.1-2ubuntu0.2+esm3, 0.26.0+dfsg.1-1.1ubuntu0.2+esm2, 0.28.4+dfsg.1-2ubuntu0.1+esm1, 1.1.0+dfsg.1-4.1ubuntu0.1+esm1, 1.7.2+ds-1ubuntu3.1, 1.9.1+ds-1ubuntu1.1 | 20.07.2026 |
SB2026072079 SB2026072444 SB2026072445 and 12 more |
||
| #VU138485 - Allocation of Resources Without Limits or Throttling CVE-2026-53585 |
CWE-770 | Medium | 0.19.0-2ubuntu0.4+esm2, 0.24.1-2ubuntu0.2+esm3, 0.26.0+dfsg.1-1.1ubuntu0.2+esm2, 0.28.4+dfsg.1-2ubuntu0.1+esm1, 1.1.0+dfsg.1-4.1ubuntu0.1+esm1, 1.7.2+ds-1ubuntu3.1, 1.9.1+ds-1ubuntu1.1 | 20.07.2026 |
SB2026072079 SB2026072444 SB2026072445 and 10 more |
||
| #VU14546 - Out-of-bounds read CVE-2018-15501 |
CWE-125 | Low | 0.19.0-2ubuntu0.4+esm2, 0.24.1-2ubuntu0.2+esm3, 0.26.0+dfsg.1-1.1ubuntu0.2+esm2, 0.28.4+dfsg.1-2ubuntu0.1+esm1, 1.1.0+dfsg.1-4.1ubuntu0.1+esm1, 1.7.2+ds-1ubuntu3.1, 1.9.1+ds-1ubuntu1.1 | 25.08.2018 |
SB2018082810 SB2018082811 SB2018102909 and 4 more |
||
| #VU11154 - Out-of-bounds read CVE-2018-8098 |
CWE-125 | Low | 0.19.0-2ubuntu0.4+esm2, 0.24.1-2ubuntu0.2+esm3, 0.26.0+dfsg.1-1.1ubuntu0.2+esm2, 0.28.4+dfsg.1-2ubuntu0.1+esm1, 1.1.0+dfsg.1-4.1ubuntu0.1+esm1, 1.7.2+ds-1ubuntu3.1, 1.9.1+ds-1ubuntu1.1 | 19.03.2018 |
SB2018030806 SB2018031236 SB2018031237 and 2 more |
||
| #VU11152 - Double Free CVE-2018-8099 |
CWE-415 | Low | 0.19.0-2ubuntu0.4+esm2, 0.24.1-2ubuntu0.2+esm3, 0.26.0+dfsg.1-1.1ubuntu0.2+esm2, 0.28.4+dfsg.1-2ubuntu0.1+esm1, 1.1.0+dfsg.1-4.1ubuntu0.1+esm1, 1.7.2+ds-1ubuntu3.1, 1.9.1+ds-1ubuntu1.1 | 19.03.2018 |
SB2018030806 SB2018102909 SB2018031236 and 3 more |
||
| #VU32000 - Memory corruption CVE-2016-10128 |
CWE-119 | High | 0.19.0-2ubuntu0.4+esm2, 0.24.1-2ubuntu0.2+esm3, 0.26.0+dfsg.1-1.1ubuntu0.2+esm2, 0.28.4+dfsg.1-2ubuntu0.1+esm1, 1.1.0+dfsg.1-4.1ubuntu0.1+esm1, 1.7.2+ds-1ubuntu3.1, 1.9.1+ds-1ubuntu1.1 | 24.03.2017 |
SB2017032404 SB2017012615 SB2017011506 and 5 more |
||
| #VU32001 - NULL Pointer Dereference CVE-2016-10129 |
CWE-476 | Medium | 0.19.0-2ubuntu0.4+esm2, 0.24.1-2ubuntu0.2+esm3, 0.26.0+dfsg.1-1.1ubuntu0.2+esm2, 0.28.4+dfsg.1-2ubuntu0.1+esm1, 1.1.0+dfsg.1-4.1ubuntu0.1+esm1, 1.7.2+ds-1ubuntu3.1, 1.9.1+ds-1ubuntu1.1 | 24.03.2017 |
SB2017032405 SB2017012616 SB2017011506 and 5 more |
||
| #VU32002 - Improper Access Control CVE-2016-10130 |
CWE-284 | Medium | 0.19.0-2ubuntu0.4+esm2, 0.24.1-2ubuntu0.2+esm3, 0.26.0+dfsg.1-1.1ubuntu0.2+esm2, 0.28.4+dfsg.1-2ubuntu0.1+esm1, 1.1.0+dfsg.1-4.1ubuntu0.1+esm1, 1.7.2+ds-1ubuntu3.1, 1.9.1+ds-1ubuntu1.1 | 24.03.2017 |
SB2017032406 SB2017012617 SB2017011506 and 5 more |