CVE-2026-53587
Public exploit code is available. Proof-of-concept or working exploit code for CVE-2026-53587 is indexed in GitHub PoC. Expect opportunistic scanning and exploitation attempts — prioritize remediation even though it is not (yet) in the CISA KEV catalog.
libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality into your application. Prior to 1.8.6 and 1.9.5, libgit2 performs a fixed-size strncmp in set_data in src/libgit2/transports/smart_pkt.c without first verifying that the smart-protocol pkt-line capability buffer contains 14 bytes. A malicious Git server can make bytes after the pkt-line complete object-format=, causing format_str to advance beyond the pkt-line and the following memchr length calculation to underflow. The resulting heap out-of-bounds walk can crash a client during the first refs-advertisement packet over HTTP, HTTPS, SSH, or the Git protocol. This issue is fixed in versions 1.8.6 and 1.9.5.
CSIRTS triage
- What
- Multiple vulnerabilities allow arbitrary command execution on remote SSH servers, credential disclosure, denial of service, and directory creation outside the repository working tree.
- Who is affected
- All deployments of libgit2 using the affected functionality are at risk.
- Urgency
- Urgent; remote code execution on SSH servers is a critical security risk with active exploitation potential.
- Action
- Apply the security update DSA-6453-1 immediately.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch CVE-2026-53587
Get an email if CVE-2026-53587 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.
Exploitation outlook
- Low exploitation risk0.39% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 32% of all EPSS-scored CVEs.
Exploit availability
Public exploit or proof-of-concept code for CVE-2026-53587 is indexed in these free datasets. Available exploit code raises real-world risk independent of the CVSS score.
- GitHub PoCPublic proof-of-concept repositories on GitHub reference this CVE.look it up ↗
Advisory coverage (3)
- highCVE-2026-53587: libgit2 is a portable C implementation of the Git core methods provided as a linkable library …nvd · 2026-08-20
- lowDSA-6453-1 libgit2 - security updatedebian · 2026-08-20
- unknownUSN-8628-1: libgit2 vulnerabilitiesubuntu · 2026-08-12
External references
Embed the live status
— this badge updates automatically when the KEV or exploit status changes. How to embed it →
[](https://www.csirts.com/cve/CVE-2026-53587)