CVE-2026-53586

Public on 2026-07-31
Modified on 2026-07-31
Description
libgit2's builtin HTTP transport follows offsite redirects for the initial smart HTTP request by default. If the redirected server then returns 401 Unauthorized, libgit2 asks the application credential callback for credentials using the original remote URL, not the redirected URL. The returned credential is then attached to the next request to the redirected host as an Authorization header.
Severity
Medium severity
Medium
See what this means
CVSS v3 Base Score
6.5
See breakdown

Affected Packages

Platform Package Release Date Advisory Status
Amazon Linux 2 - Core git Not Affected
Amazon Linux 2023 git Not Affected
Amazon Linux 2023 libgit2 Pending Fix
Amazon Linux 2 - Core rust 2026-08-17 ALAS2-2026-3865 Fixed
Amazon Linux 2023 rust 2026-08-17 ALAS2023-2026-2065 Fixed

CVSS Scores

Score Type Score Vector
Amazon Linux CVSSv3 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N