Insufficiently protected credentials in libgit2 - CVE-2026-53586

 

Insufficiently protected credentials in libgit2 - CVE-2026-53586

Published: July 20, 2026


Vulnerability identifier: #VU138490
CSH Severity: Medium
CVSS v4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2026-53586
CWE-ID: CWE-522
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: libgit2.github.com
Affected software:
libgit2

Detailed vulnerability description

The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to insufficiently protected credentials in the builtin HTTP transport when following an offsite redirect for the initial smart HTTP request and handling a 401 authentication challenge from the redirected server. A remote attacker can cause an initial offsite redirect from a trusted Git remote URL to disclose sensitive information.

User interaction is required to contact a trusted original URL for which the application is willing to provide credentials.


How to mitigate CVE-2026-53586

Install security update from vendor's website.

Sources