Insufficiently protected credentials in libgit2 - CVE-2026-53586
Published: July 20, 2026
libgit2
Detailed vulnerability description
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to insufficiently protected credentials in the builtin HTTP transport when following an offsite redirect for the initial smart HTTP request and handling a 401 authentication challenge from the redirected server. A remote attacker can cause an initial offsite redirect from a trusted Git remote URL to disclose sensitive information.
User interaction is required to contact a trusted original URL for which the application is willing to provide credentials.