Known vulnerabilities in libgit2 1.9.4

Software: libgit2
Version: 1.9.4
Software CPE: cpe:2.3:a:libgit2_github_com:libgit2:*:*:*:*:*:*:*:*
Total vulnerabilities: 7
Public exploits: 0
Known exploited (KEV): 0
Highest CVSSv4 Score: 8.8

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting libgit2 version 1.9.4 libgit2 1.9.4 is affected by 7 vulnerabilities: 1 high, 5 medium, 1 low Critical High Medium Low

Vulnerabilities (7)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU143594 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2026-5917
CWE-78 High
No
No
1.8.7, 1.9.7 16.08.2026 SB20260816530
SB2026081711
SB2026081712
and 7 more
#VU138491 - Improper Validation of Certificate with Host Mismatch
CVE-2026-53583
CWE-297 Medium
No
No
1.8.6, 1.9.5 20.07.2026 SB2026072079
SB2026072444
SB2026072445
and 9 more
#VU138490 - Insufficiently Protected Credentials
CVE-2026-53586
CWE-522 Medium
No
No
1.9.5 20.07.2026 SB2026072079
SB2026072444
SB2026072445
and 10 more
#VU138489 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2026-53584
CWE-22 Low
No
No
1.8.6, 1.9.5 20.07.2026 SB2026072079
SB2026072444
SB2026072445
and 10 more
#VU138487 - Out-of-bounds read
CVE-2026-53587
CWE-125 Medium
No
No
1.9.5 20.07.2026 SB2026072079
SB2026072444
SB2026072445
and 10 more
#VU138486 - Heap-based Buffer Overflow
CWE-122 Medium
No
No
1.8.6, 1.9.5 20.07.2026 SB2026072079
#VU138485 - Allocation of Resources Without Limits or Throttling
CVE-2026-53585
CWE-770 Medium
No
No
1.8.6, 1.9.5 20.07.2026 SB2026072079
SB2026072444
SB2026072445
and 10 more