CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-53587

highpublic exploitCVSS 7.5covered by 3 sourcesfirst seen 2026-08-12
Public exploit code is available. Proof-of-concept or working exploit code for CVE-2026-53587 is indexed in GitHub PoC. Expect opportunistic scanning and exploitation attempts — prioritize remediation even though it is not (yet) in the CISA KEV catalog.
libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality into your application. Prior to 1.8.6 and 1.9.5, libgit2 performs a fixed-size strncmp in set_data in src/libgit2/transports/smart_pkt.c without first verifying that the smart-protocol pkt-line capability buffer contains 14 bytes. A malicious Git server can make bytes after the pkt-line complete object-format=, causing format_str to advance beyond the pkt-line and the following memchr length calculation to underflow. The resulting heap out-of-bounds walk can crash a client during the first refs-advertisement packet over HTTP, HTTPS, SSH, or the Git protocol. This issue is fixed in versions 1.8.6 and 1.9.5.

CSIRTS triage

What
Multiple vulnerabilities allow arbitrary command execution on remote SSH servers, credential disclosure, denial of service, and directory creation outside the repository working tree.
Who is affected
All deployments of libgit2 using the affected functionality are at risk.
Urgency
Urgent; remote code execution on SSH servers is a critical security risk with active exploitation potential.
Action
Apply the security update DSA-6453-1 immediately.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-53587

Get an email if CVE-2026-53587 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Exploit availability

Public exploit or proof-of-concept code for CVE-2026-53587 is indexed in these free datasets. Available exploit code raises real-world risk independent of the CVSS score.

Advisory coverage (3)

External references

NVD record for CVE-2026-53587

CVE.org record

Embed the live status

CVE-2026-53587 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-53587 status](https://www.csirts.com/badge/CVE-2026-53587)](https://www.csirts.com/cve/CVE-2026-53587)