← Vulnerability feed

Vulnerability record · CVE-2023-22742 · published 20 January 2023

CVE-2023-22742: Libgit2 improper verification of cryptographic signature vulnerability

Libgit2 · Libgit2

libgit2 is a cross-platform, linkable library implementation of Git. When using an SSH remote with the optional libssh2 backend, libgit2 does not perform certificate checking by default. Prior versions of libgit2 require the caller to set the `certificate_check` field of libgit2's `git_remote_callbacks` structure - if a certificate check callback is not set, libgit2 does not perform any certificate checking. This means that by default - without configuring a certificate check callback, clients will not perform validation on the server SSH keys and may be subject to a man-in-the-middle attack. Users are encouraged to upgrade to v1.4.5 or v1.5.1. Users unable to upgrade should ensure that all relevant certificates are manually checked.

5.9 CVSS 3.1 Medium EPSS 0.58% · top 54.5% CWE-347 · Improper verification of cryptographic signature
5.9CVSS 3.1 base score
0.58%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
14References
17 Jun 2026Last modified by NVD

Description

libgit2 is a cross-platform, linkable library implementation of Git. When using an SSH remote with the optional libssh2 backend, libgit2 does not perform certificate checking by default. Prior versions of libgit2 require the caller to set the `certificate_check` field of libgit2's `git_remote_callbacks` structure - if a certificate check callback is not set, libgit2 does not perform any certificate checking. This means that by default - without configuring a certificate check callback, clients will not perform validation on the server SSH keys and may be subject to a man-in-the-middle attack. Users are encouraged to upgrade to v1.4.5 or v1.5.1. Users unable to upgrade should ensure that all relevant certificates are manually checked.

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-22742 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-24577Libgit2 heap-based buffer overflow vulnerabilitylibgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality i…EPSS 1.5%9.8CVE-2020-12278Libgit2 vulnerabilityAn issue was discovered in libgit2 before 0.28.4 and 0.9x before 0.99.0. path.c mishandles equivalent filenames that exist because of NTFS Alternate …EPSS 5.2%9.8CVE-2020-12279Libgit2 vulnerabilityAn issue was discovered in libgit2 before 0.28.4 and 0.9x before 0.99.0. checkout.c mishandles equivalent filenames that exist because of NTFS short …EPSS 5.2%9.8CVE-2014-9390Git clients execute commands via crafted .git/config on case-insensitive filesystemsGit, Mercurial, libgit2, JGit, EGit and Xcode mishandle crafted .git/config paths on Windows and OS X, allowing a remote repository to place a file t…EPSS 76%analysed8.1CVE-2018-10887Libgit2 out-of-bounds read vulnerabilityA flaw was found in libgit2 before version 0.27.3. It has been discovered that an unexpected sign extension in git_delta_apply function in delta.c fi…EPSS 2.1%7.5CVE-2024-24575Libgit2 uncontrolled resource consumption vulnerabilitylibgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality i…EPSS 1.4%7.5CVE-2018-15501Debian linux out-of-bounds read vulnerabilityIn ng_pkt in transports/smart_pkt.c in libgit2 before 0.26.6 and 0.27.x before 0.27.4, a remote attacker can send a crafted smart-protocol "ng" packe…EPSS 4.4%6.5CVE-2018-10888Libgit2 improper input validation vulnerabilityA flaw was found in libgit2 before version 0.27.3. A missing check in git_delta_apply function in delta.c file, may lead to an out-of-bound read whil…EPSS 1.8%

Source: NIST National Vulnerability Database (record CVE-2023-22742), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.