CVE-2026-53586
Public on 2026-07-31
Modified on 2026-07-31
Description
libgit2's builtin HTTP transport follows offsite redirects for the initial smart HTTP request by default. If the redirected server then returns 401 Unauthorized, libgit2 asks the application credential callback for credentials using the original remote URL, not the redirected URL. The returned credential is then attached to the next request to the redirected host as an Authorization header.
Severity
See what this means
CVSS v3 Base Score
See breakdown
Affected Packages
| Platform | Package | Release Date | Advisory | Status |
|---|---|---|---|---|
| Amazon Linux 2 - Core | git | Not Affected | ||
| Amazon Linux 2023 | git | Not Affected | ||
| Amazon Linux 2023 | libgit2 | Pending Fix | ||
| Amazon Linux 2 - Core | rust | Pending Fix | ||
| Amazon Linux 2023 | rust | Pending Fix |
CVSS Scores
| Score Type | Score | Vector | |
|---|---|---|---|
| Amazon Linux | CVSSv3 | 6.5 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N |