๐Ÿ” CVE Alert

CVE-2026-53585

MEDIUM 5.3

libgit2: Unbounded Memory Allocation via Delta Object Result-Size Header

CVSS Score
5.3
EPSS Score
0.0%
EPSS Percentile
0th

libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality into your application. Prior to 1.8.6 and 1.9.5, git_delta_apply in src/libgit2/delta.c trusts the attacker-controlled res_sz value parsed by hdr_sz from a delta object header and passes that amount to git__malloc before validating delta instructions. Malicious pack data supplied through git_clone, git_fetch, git_remote_fetch, git_indexer_append, or a local attacker-supplied repository can use a very small multi-level OFS_DELTA chain to retain extremely large allocations and exhaust memory. This issue is fixed in versions 1.8.6 and 1.9.5.

CWE CWE-770
Vendor libgit2
Product libgit2
Published Aug 20, 2026
Stay Ahead of the Next One

Get instant alerts for libgit2 libgit2

Be the first to know when new medium vulnerabilities affecting libgit2 libgit2 are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
Low

Affected Versions

libgit2 / libgit2
< 1.8.6 >= 1.9.0, < 1.9.5

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/libgit2/libgit2/security/advisories/GHSA-27m5-gxxh-x79j github.com: https://github.com/libgit2/libgit2/commit/0cdfdd5fa8f8514c82413025e1e0808866cf7c30 github.com: https://github.com/libgit2/libgit2/commit/c1896f06df22cc0ca5658df3a8f6cd7ede4cd6ae github.com: https://github.com/libgit2/libgit2/commit/dec22ac01ad9620c96b7b9ac3ef636ea46d43bed github.com: https://github.com/libgit2/libgit2/releases/tag/v1.8.6 github.com: https://github.com/libgit2/libgit2/releases/tag/v1.9.5