CVE Tools

Libgit2

4 CVEs tracked since 2018. Since Mar 2018, none of them reached CISA KEV.

Libgit2 CVEs per month

Mar 2018 to Jul 2018. Point at a month, or focus the strip and use the arrow keys.
Libgit2 CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2018-0320
2018-04null or fewer
2018-05null or fewer
2018-06null or fewer
2018-0720

Products

The products that kept showing up in Libgit2's monthly top three, with their CVEs summed over those months.

  1. Libgit242 months

Latest CVEs

The 15 most recently published vulnerabilities affecting Libgit2.

  1. CVE-2026-53586libgit2: HTTP transport can leak credentials to an offsite redirect target6.5
  2. CVE-2026-53583libgit2: Inverted IP SubjectAltName Comparison in OpenSSL Backend6.5
  3. CVE-2026-53585libgit2: Unbounded Memory Allocation via Delta Object Result-Size Header5.3
  4. CVE-2026-53587libgit2 - Unauthenticated network-reachable heap out-of-bounds read in transports/smart_pkt.c:set_data7.5
  5. CVE-2026-53584libgit2: Submodule path traversal4.3
  6. CVE-2026-5917libgit2 Shell Command Injection via ssh_libssh2 Backend8.8
  7. CVE-2024-24577libgit2 is vulnerable to arbitrary code execution due to heap corruption in `git_index_add`8.6
  8. CVE-2024-24575libgit2 is vulnerable to a denial of service attack in `git_revparse_single`7.5
  9. CVE-2023-22742libgit2 fails to verify SSH keys by default5.3
  10. CVE-2020-12278An issue was discovered in libgit2 before 0.28.4 and 0.9x before 0.99.0. path.c mishandles equivalent filenames that exist because of NTFS Alternate Data Streams. This may allow remote code executi...9.8
  11. CVE-2020-12279An issue was discovered in libgit2 before 0.28.4 and 0.9x before 0.99.0. checkout.c mishandles equivalent filenames that exist because of NTFS short names. This may allow remote code execution when...9.8
  12. CVE-2014-9390Git before 1.8.5.6, 1.9.x before 1.9.5, 2.0.x before 2.0.5, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 on Windows and OS X; Mercurial before 3.2.3 on Windows and OS X; Apple Xcode before 6.2 beta 3...9.8
  13. CVE-2018-15501In ng_pkt in transports/smart_pkt.c in libgit2 before 0.26.6 and 0.27.x before 0.27.4, a remote attacker can send a crafted smart-protocol "ng" packet that lacks a '\0' byte to trigger an out-of-bo...7.5
  14. CVE-2018-10888A flaw was found in libgit2 before version 0.27.3. A missing check in git_delta_apply function in delta.c file, may lead to an out-of-bound read while reading a binary delta file. An attacker may u...6.5
  15. CVE-2018-10887A flaw was found in libgit2 before version 0.27.3. It has been discovered that an unexpected sign extension in git_delta_apply function in delta.c file may lead to an integer overflow which in turn...8.1

The record

Peak rank
#186 in Mar 2018
Busiest month shown
Mar 2018, 2 CVEs
Months with a KEV entry
0 since Mar 2018
Monthly snapshots
2 since 2018
Libgit2's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store