Known vulnerabilities in libgit2

Software: libgit2
Software CPE: cpe:2.3:a:libgit2_github_com:libgit2:*:*:*:*:*:*:*:*
Total vulnerabilities: 24
Public exploits: 0
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting libgit2 libgit2 is affected by 24 known vulnerabilities: 3 high, 12 medium, 9 low Critical High Medium Low

Vulnerabilities (24)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU143594 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2026-5917
CWE-78 High
No
No
1.8.7, 1.9.7 16.08.2026 SB20260816530
SB2026081711
SB2026081712
and 7 more
#VU138491 - Improper Validation of Certificate with Host Mismatch
CVE-2026-53583
CWE-297 Medium
No
No
1.8.6, 1.9.5 20.07.2026 SB2026072079
SB2026072444
SB2026072445
and 9 more
#VU138490 - Insufficiently Protected Credentials
CVE-2026-53586
CWE-522 Medium
No
No
1.9.5 20.07.2026 SB2026072079
SB2026072444
SB2026072445
and 10 more
#VU138489 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2026-53584
CWE-22 Low
No
No
1.8.6, 1.9.5 20.07.2026 SB2026072079
SB2026072444
SB2026072445
and 10 more
#VU138487 - Out-of-bounds read
CVE-2026-53587
CWE-125 Medium
No
No
1.9.5 20.07.2026 SB2026072079
SB2026072444
SB2026072445
and 10 more
#VU138486 - Heap-based Buffer Overflow
CWE-122 Medium
No
No
1.8.6, 1.9.5 20.07.2026 SB2026072079
#VU138485 - Allocation of Resources Without Limits or Throttling
CVE-2026-53585
CWE-770 Medium
No
No
1.8.6, 1.9.5 20.07.2026 SB2026072079
SB2026072444
SB2026072445
and 10 more
#VU86204 - Use of Incorrectly-Resolved Name or Reference
CVE-2020-12279
CWE-706 Medium
No
No
0.28.4, 0.99.0 07.02.2024 SB2020042733
SB2024030562
SB2021072794
#VU86203 - Use of Incorrectly-Resolved Name or Reference
CVE-2020-12278
CWE-706 Medium
No
No
0.28.4, 0.99.0 07.02.2024 SB2020042733
SB2024030562
SB2021072794
#VU86202 - Loop with Unreachable Exit Condition ('Infinite Loop')
CVE-2024-24575
CWE-835 Medium
No
No
1.6.5, 1.7.2 07.02.2024 SB2024020715
SB2024020801
SB2024020863
and 15 more
#VU86201 - Heap-based Buffer Overflow
CVE-2024-24577
CWE-122 High
No
No
1.6.5, 1.7.2 07.02.2024 SB2024020715
SB2024020801
SB2024020863
and 29 more
#VU71412 - Configuration
CVE-2023-22742
CWE-16 Low
No
No
1.4.5, 1.5.1 22.01.2023 SB2023012216
SB2023032438
SB2023040667
and 4 more
#VU65287 - Permissions, Privileges, and Access Controls
CVE-2022-29187
CWE-264 Medium
No
No
1.3.2, 1.4.4 13.07.2022 SB2022071347
SB2022071348
SB2022071350
and 30 more
#VU62258 - Untrusted Search Path
CVE-2022-24765
CWE-426 Low
No
No
1.3.2, 1.4.4 12.04.2022 SB2022041262
SB2022041264
SB2022041265
and 44 more
#VU14546 - Out-of-bounds read
CVE-2018-15501
CWE-125 Low
No
No
0.26.6, 0.27.4 25.08.2018 SB2018082810
SB2018082811
SB2018102909
and 4 more
#VU13843 - Out-of-bounds read
CVE-2018-10888
CWE-125 Low
No
No
0.26.5, 0.27.3 12.07.2018 SB2018071206
SB2018082811
SB2018102909
and 5 more
#VU13842 - Integer overflow
CVE-2018-10887
CWE-125 Low
No
No
0.26.5, 0.27.3 11.07.2018 SB2018071206
SB2018082811
SB2018102909
and 5 more
#VU11154 - Out-of-bounds read
CVE-2018-8098
CWE-125 Low
No
No
- 19.03.2018 SB2018030806
SB2018031236
SB2018031237
and 2 more
#VU11152 - Double Free
CVE-2018-8099
CWE-415 Low
No
No
- 19.03.2018 SB2018030806
SB2018102909
SB2018031236
and 3 more
#VU32002 - Improper Access Control
CVE-2016-10130
CWE-284 Medium
No
No
- 24.03.2017 SB2017032406
SB2017012617
SB2017011506
and 5 more


Showing elements 1 - 20 out of 24