Junglewise Threat Intelligence

CVE-2026-53585: libgit2 delta parsing memory exhaustion

CVE-2026-53585 · Severity: medium · CVSS 5.3 · Published 2026-08-20

Technologies: Libgit2.

Executive brief

libgit2 is a library that implements Git core functionality within applications. An attacker can craft malicious Git repository data or pack files that cause the library to allocate and retain extremely large amounts of memory, exhausting available system resources and crashing applications that depend on libgit2 for cloning, fetching, or processing repositories.

Technical details

The vulnerability exists in the git_delta_apply function (src/libgit2/delta.c) which trusts an attacker-controlled res_sz value parsed from a delta object header without proper validation. This value is passed to git__malloc before delta instructions are validated, allowing attackers to trigger excessive memory allocation. Malicious data can be supplied through git_clone, git_fetch, git_remote_fetch, git_indexer_append, or a local repository using specially crafted multi-level OFS_DELTA chains. The fix involves introducing GIT_OPT_SET_PACK_MAX_OBJECT_SIZE setting to reject objects larger than 2 GiB by default, available in versions 1.8.6 and 1.9.5.

Affected products

  • libgit2 libgit2 before 1.8.6 and 1.9.5

Timeline

  • 2026-08-20: disclosed
  • 2026-08-20: patched: Fixed in libgit2 1.8.6 and 1.9.5

References