← Back to feed
Vulnerabilities & PatchesEmerging1 sourceAug 20, 2026 · 18:40via CVEFeed

CVE-2026-53586 - libgit2: HTTP transport can leak credentials to an offsite redirect target

Brief

CVE ID : CVE-2026-53586

Published : Aug. 20, 2026, 6:40 p. m.

  • 29 minutes ago

Description : libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality into your application. Prior to 1.

  • 6 and 1.
  • 5, the built-in HTTP transport in src/libgit2/transports/http. c follows an offsite initial redirect, and handle_remote_auth and handle_auth pass transport-owner-url instead of transport-server.

url to the credential callback when the redirected host returns 401 Unauthorized. A callback that scopes credentials to the original trusted URL can therefore return GIT_CREDENTIAL_USERPASS_PLAINTEXT credentials that libgit2 stores in transport-server. cred and sends as an Authorization header to the redirected host.

Read more on CVEFeed