libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality into your application. Prior to 1.8.6 and 1.9.5, verifyservercert in src/libgit2/streams/openssl.c uses an inverted !!memcmp result in the GEN_IPADD branch when comparing an IP-literal host with a certificate IP SubjectAltName. OpenSSL builds reject matching IP addresses and accept mismatched IP addresses, allowing a network attacker with a CA-trusted certificate containing any IP SubjectAltName to intercept libgit2 connections to IP-literal HTTPS URLs. DNS SubjectAltName validation and non-OpenSSL TLS backends are not affected. This issue is fixed in versions 1.8.6 and 1.9.5.
{
"cwe_ids": [
"CWE-295",
"CWE-297"
],
"cna_assigner": "GitHub_M",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/53xxx/CVE-2026-53583.json"
}{
"source": [
"AFFECTED_FIELD",
"REFERENCES"
],
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "1.8.6"
},
{
"introduced": "1.9.0"
},
{
"fixed": "1.9.5"
}
]
}
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-53583.json"
[
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"161163592757564595969332526842759641351",
"211848842349138299922078898038780968212",
"150678553108198291235507343758851396879",
"243595294194876164507250832174148284305",
"260389537651659206423006796518091961514",
"111247752267490302524130105154936124555",
"157166958937368593972319777643047511994",
"14077685195833109481790633948365565836",
"211479020404053345239813664263127410790",
"158673971632547545414188081025559933918",
"236782617318123956231007559998755265225",
"160046562868851252895684686586687525125",
"30857154250935804666614266446734606942",
"154944407122117528254105116676392307560",
"287732400818321933112008560485550651873",
"133646563724366978894573886906506650712"
]
},
"signature_type": "Line",
"signature_version": "v1",
"id": "CVE-2026-53583-559c06d2",
"source": "https://github.com/libgit2/libgit2/commit/ef086bc3e4eedf62be38a910381aae24d49871ff",
"target": {
"file": "src/libgit2/streams/openssl.c"
},
"deprecated": false
},
{
"digest": {
"function_hash": "194443070578024260421714920149812272884",
"length": 2323.0
},
"signature_type": "Function",
"signature_version": "v1",
"id": "CVE-2026-53583-77a13ab1",
"source": "https://github.com/libgit2/libgit2/commit/ef086bc3e4eedf62be38a910381aae24d49871ff",
"target": {
"file": "src/libgit2/streams/openssl.c",
"function": "verify_server_cert"
},
"deprecated": false
},
{
"digest": {
"function_hash": "194443070578024260421714920149812272884",
"length": 2323.0
},
"signature_type": "Function",
"signature_version": "v1",
"id": "CVE-2026-53583-a9d9ed68",
"source": "https://github.com/libgit2/libgit2/commit/c2aa35409ee0e6515df64da49750f13a0a42c47f",
"target": {
"file": "src/libgit2/streams/openssl.c",
"function": "verify_server_cert"
},
"deprecated": false
},
{
"digest": {
"function_hash": "194443070578024260421714920149812272884",
"length": 2323.0
},
"signature_type": "Function",
"signature_version": "v1",
"id": "CVE-2026-53583-b59b2bd1",
"source": "https://github.com/libgit2/libgit2/commit/647dcb432980b84ede4cb5a008bbd1ccb4ead03d",
"target": {
"file": "src/libgit2/streams/openssl.c",
"function": "verify_server_cert"
},
"deprecated": false
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"161163592757564595969332526842759641351",
"211848842349138299922078898038780968212",
"150678553108198291235507343758851396879",
"243595294194876164507250832174148284305",
"260389537651659206423006796518091961514",
"111247752267490302524130105154936124555",
"157166958937368593972319777643047511994",
"14077685195833109481790633948365565836",
"211479020404053345239813664263127410790",
"158673971632547545414188081025559933918",
"236782617318123956231007559998755265225",
"160046562868851252895684686586687525125",
"30857154250935804666614266446734606942",
"154944407122117528254105116676392307560",
"287732400818321933112008560485550651873",
"133646563724366978894573886906506650712"
]
},
"signature_type": "Line",
"signature_version": "v1",
"id": "CVE-2026-53583-c2a6ac27",
"source": "https://github.com/libgit2/libgit2/commit/c2aa35409ee0e6515df64da49750f13a0a42c47f",
"target": {
"file": "src/libgit2/streams/openssl.c"
},
"deprecated": false
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"161163592757564595969332526842759641351",
"211848842349138299922078898038780968212",
"150678553108198291235507343758851396879",
"243595294194876164507250832174148284305",
"260389537651659206423006796518091961514",
"111247752267490302524130105154936124555",
"157166958937368593972319777643047511994",
"14077685195833109481790633948365565836",
"211479020404053345239813664263127410790",
"158673971632547545414188081025559933918",
"236782617318123956231007559998755265225",
"160046562868851252895684686586687525125",
"30857154250935804666614266446734606942",
"154944407122117528254105116676392307560",
"287732400818321933112008560485550651873",
"133646563724366978894573886906506650712"
]
},
"signature_type": "Line",
"signature_version": "v1",
"id": "CVE-2026-53583-cfe6bfb2",
"source": "https://github.com/libgit2/libgit2/commit/647dcb432980b84ede4cb5a008bbd1ccb4ead03d",
"target": {
"file": "src/libgit2/streams/openssl.c"
},
"deprecated": false
}
]
"2026-08-22T10:47:45Z"