Known vulnerabilities in libgit2 (Debian package)

Vendor: Debian
Software CPE: cpe:2.3:o:debian:libgit2_debian_package:*:*:*:*:*:debian_linux:*:*
Total vulnerabilities: 8
Public exploits: 0
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.2

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting libgit2 (Debian package) libgit2 (Debian package) is affected by 8 known vulnerabilities: 2 high, 5 medium, 1 low Critical High Medium Low

Vulnerabilities (8)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU143594 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2026-5917
CWE-78 High
No
No
1.9.0+ds-2+deb13u1 16.08.2026 SB20260816530
SB2026081711
SB2026081712
and 7 more
#VU138491 - Improper Validation of Certificate with Host Mismatch
CVE-2026-53583
CWE-297 Medium
No
No
1.9.0+ds-2+deb13u1 20.07.2026 SB2026072079
SB2026072444
SB2026072445
and 9 more
#VU138490 - Insufficiently Protected Credentials
CVE-2026-53586
CWE-522 Medium
No
No
1.9.0+ds-2+deb13u1 20.07.2026 SB2026072079
SB2026072444
SB2026072445
and 10 more
#VU138489 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2026-53584
CWE-22 Low
No
No
1.9.0+ds-2+deb13u1 20.07.2026 SB2026072079
SB2026072444
SB2026072445
and 10 more
#VU138487 - Out-of-bounds read
CVE-2026-53587
CWE-125 Medium
No
No
1.9.0+ds-2+deb13u1 20.07.2026 SB2026072079
SB2026072444
SB2026072445
and 10 more
#VU138485 - Allocation of Resources Without Limits or Throttling
CVE-2026-53585
CWE-770 Medium
No
No
1.9.0+ds-2+deb13u1 20.07.2026 SB2026072079
SB2026072444
SB2026072445
and 10 more
#VU86202 - Loop with Unreachable Exit Condition ('Infinite Loop')
CVE-2024-24575
CWE-835 Medium
No
No
1.1.0+dfsg.1-4+deb11u2, 1.5.1+ds-1+deb12u1 07.02.2024 SB2024020715
SB2024020801
SB2024020863
and 15 more
#VU86201 - Heap-based Buffer Overflow
CVE-2024-24577
CWE-122 High
No
No
1.1.0+dfsg.1-4+deb11u2, 1.5.1+ds-1+deb12u1 07.02.2024 SB2024020715
SB2024020801
SB2024020863
and 29 more