git2
Activity
- Latest release
- 3mo ago
- Total releases
- 125
- Cadence
- ~26 days
- Last 12 months
- 3
Details
- License
- MIT OR Apache-2.0
- First release
- Nov 14, 2014
| Version | Released | |
|---|---|---|
0.21.0
unknown
|
0.21.0
unknown
Dependencies (11)
+ 3 more |
|
0.20.4
unknown
2 CVEs
RUSTSEC-2026-0184
May 13, 2026
Potential undefined behavior with Signature from a buffer-created BlameHunk When a Fixed in
0.21.0
References Updated Jun 17, 2026 · Source: OSV.dev
RUSTSEC-2026-0183
May 12, 2026
Potential undefined behavior when calling Remote::list() When calling Fixed in
0.21.0
References Updated Jun 17, 2026 · Source: OSV.dev |
0.20.4
unknown
Dependencies (10)
+ 2 more |
|
0.20.3
unknown
3 CVEs
RUSTSEC-2026-0184
May 13, 2026
Potential undefined behavior with Signature from a buffer-created BlameHunk When a Fixed in
0.21.0
References Updated Jun 17, 2026 · Source: OSV.dev
RUSTSEC-2026-0183
May 12, 2026
Potential undefined behavior when calling Remote::list() When calling Fixed in
0.21.0
References Updated Jun 17, 2026 · Source: OSV.dev
GHSA-j39j-6gw9-jw6h
RUSTSEC-2026-0008
Feb 04, 2026
git2 has potential undefined behavior when dereferencing Buf struct
Low
Network
Low
None
None
If the Buf struct is dereferenced immediately after calling new() or default() on the Buf struct, a null pointer is passed to the unsafe function slice::from_raw_parts. According to the safety section documentation of the function, data must be non-null and aligned even for zero-length slices or slices of ZSTs. Thus, passing a null pointer will lead to undefined behavior. Fixed in
0.20.4
References Updated Sep 10, 2026 · Source: OSV.dev |
0.20.3
unknown
Dependencies (10)
+ 2 more |
|
0.20.2
unknown
3 CVEs
RUSTSEC-2026-0184
May 13, 2026
Potential undefined behavior with Signature from a buffer-created BlameHunk When a Fixed in
0.21.0
References Updated Jun 17, 2026 · Source: OSV.dev
RUSTSEC-2026-0183
May 12, 2026
Potential undefined behavior when calling Remote::list() When calling Fixed in
0.21.0
References Updated Jun 17, 2026 · Source: OSV.dev
GHSA-j39j-6gw9-jw6h
RUSTSEC-2026-0008
Feb 04, 2026
git2 has potential undefined behavior when dereferencing Buf struct
Low
Network
Low
None
None
If the Buf struct is dereferenced immediately after calling new() or default() on the Buf struct, a null pointer is passed to the unsafe function slice::from_raw_parts. According to the safety section documentation of the function, data must be non-null and aligned even for zero-length slices or slices of ZSTs. Thus, passing a null pointer will lead to undefined behavior. Fixed in
0.20.4
References Updated Sep 10, 2026 · Source: OSV.dev |
0.20.2
unknown
Dependencies (10)
+ 2 more |
|
0.20.1
unknown
3 CVEs
RUSTSEC-2026-0184
May 13, 2026
Potential undefined behavior with Signature from a buffer-created BlameHunk When a Fixed in
0.21.0
References Updated Jun 17, 2026 · Source: OSV.dev
RUSTSEC-2026-0183
May 12, 2026
Potential undefined behavior when calling Remote::list() When calling Fixed in
0.21.0
References Updated Jun 17, 2026 · Source: OSV.dev
GHSA-j39j-6gw9-jw6h
RUSTSEC-2026-0008
Feb 04, 2026
git2 has potential undefined behavior when dereferencing Buf struct
Low
Network
Low
None
None
If the Buf struct is dereferenced immediately after calling new() or default() on the Buf struct, a null pointer is passed to the unsafe function slice::from_raw_parts. According to the safety section documentation of the function, data must be non-null and aligned even for zero-length slices or slices of ZSTs. Thus, passing a null pointer will lead to undefined behavior. Fixed in
0.20.4
References Updated Sep 10, 2026 · Source: OSV.dev |
0.20.1
unknown
Dependencies (10)
+ 2 more |
|
0.20.0
unknown
3 CVEs
RUSTSEC-2026-0184
May 13, 2026
Potential undefined behavior with Signature from a buffer-created BlameHunk When a Fixed in
0.21.0
References Updated Jun 17, 2026 · Source: OSV.dev
RUSTSEC-2026-0183
May 12, 2026
Potential undefined behavior when calling Remote::list() When calling Fixed in
0.21.0
References Updated Jun 17, 2026 · Source: OSV.dev
GHSA-j39j-6gw9-jw6h
RUSTSEC-2026-0008
Feb 04, 2026
git2 has potential undefined behavior when dereferencing Buf struct
Low
Network
Low
None
None
If the Buf struct is dereferenced immediately after calling new() or default() on the Buf struct, a null pointer is passed to the unsafe function slice::from_raw_parts. According to the safety section documentation of the function, data must be non-null and aligned even for zero-length slices or slices of ZSTs. Thus, passing a null pointer will lead to undefined behavior. Fixed in
0.20.4
References Updated Sep 10, 2026 · Source: OSV.dev |
0.20.0
unknown
Dependencies (10)
+ 2 more |
|
0.19.0
unknown
3 CVEs
RUSTSEC-2026-0184
May 13, 2026
Potential undefined behavior with Signature from a buffer-created BlameHunk When a Fixed in
0.21.0
References Updated Jun 17, 2026 · Source: OSV.dev
RUSTSEC-2026-0183
May 12, 2026
Potential undefined behavior when calling Remote::list() When calling Fixed in
0.21.0
References Updated Jun 17, 2026 · Source: OSV.dev
GHSA-j39j-6gw9-jw6h
RUSTSEC-2026-0008
Feb 04, 2026
git2 has potential undefined behavior when dereferencing Buf struct
Low
Network
Low
None
None
If the Buf struct is dereferenced immediately after calling new() or default() on the Buf struct, a null pointer is passed to the unsafe function slice::from_raw_parts. According to the safety section documentation of the function, data must be non-null and aligned even for zero-length slices or slices of ZSTs. Thus, passing a null pointer will lead to undefined behavior. Fixed in
0.20.4
References Updated Sep 10, 2026 · Source: OSV.dev |
0.19.0
unknown
Dependencies (10)
+ 2 more |
|
0.18.3
unknown
3 CVEs
RUSTSEC-2026-0184
May 13, 2026
Potential undefined behavior with Signature from a buffer-created BlameHunk When a Fixed in
0.21.0
References Updated Jun 17, 2026 · Source: OSV.dev
RUSTSEC-2026-0183
May 12, 2026
Potential undefined behavior when calling Remote::list() When calling Fixed in
0.21.0
References Updated Jun 17, 2026 · Source: OSV.dev
GHSA-j39j-6gw9-jw6h
RUSTSEC-2026-0008
Feb 04, 2026
git2 has potential undefined behavior when dereferencing Buf struct
Low
Network
Low
None
None
If the Buf struct is dereferenced immediately after calling new() or default() on the Buf struct, a null pointer is passed to the unsafe function slice::from_raw_parts. According to the safety section documentation of the function, data must be non-null and aligned even for zero-length slices or slices of ZSTs. Thus, passing a null pointer will lead to undefined behavior. Fixed in
0.20.4
References Updated Sep 10, 2026 · Source: OSV.dev |
0.18.3
unknown
Dependencies (10)
+ 2 more |
|
0.18.2
unknown
3 CVEs
RUSTSEC-2026-0184
May 13, 2026
Potential undefined behavior with Signature from a buffer-created BlameHunk When a Fixed in
0.21.0
References Updated Jun 17, 2026 · Source: OSV.dev
RUSTSEC-2026-0183
May 12, 2026
Potential undefined behavior when calling Remote::list() When calling Fixed in
0.21.0
References Updated Jun 17, 2026 · Source: OSV.dev
GHSA-j39j-6gw9-jw6h
RUSTSEC-2026-0008
Feb 04, 2026
git2 has potential undefined behavior when dereferencing Buf struct
Low
Network
Low
None
None
If the Buf struct is dereferenced immediately after calling new() or default() on the Buf struct, a null pointer is passed to the unsafe function slice::from_raw_parts. According to the safety section documentation of the function, data must be non-null and aligned even for zero-length slices or slices of ZSTs. Thus, passing a null pointer will lead to undefined behavior. Fixed in
0.20.4
References Updated Sep 10, 2026 · Source: OSV.dev |
0.18.2
unknown
Dependencies (10)
+ 2 more |
|
0.18.1
unknown
3 CVEs
RUSTSEC-2026-0184
May 13, 2026
Potential undefined behavior with Signature from a buffer-created BlameHunk When a Fixed in
0.21.0
References Updated Jun 17, 2026 · Source: OSV.dev
RUSTSEC-2026-0183
May 12, 2026
Potential undefined behavior when calling Remote::list() When calling Fixed in
0.21.0
References Updated Jun 17, 2026 · Source: OSV.dev
GHSA-j39j-6gw9-jw6h
RUSTSEC-2026-0008
Feb 04, 2026
git2 has potential undefined behavior when dereferencing Buf struct
Low
Network
Low
None
None
If the Buf struct is dereferenced immediately after calling new() or default() on the Buf struct, a null pointer is passed to the unsafe function slice::from_raw_parts. According to the safety section documentation of the function, data must be non-null and aligned even for zero-length slices or slices of ZSTs. Thus, passing a null pointer will lead to undefined behavior. Fixed in
0.20.4
References Updated Sep 10, 2026 · Source: OSV.dev |
0.18.1
unknown
Dependencies (10)
+ 2 more |
|
0.18.0
unknown
3 CVEs
RUSTSEC-2026-0184
May 13, 2026
Potential undefined behavior with Signature from a buffer-created BlameHunk When a Fixed in
0.21.0
References Updated Jun 17, 2026 · Source: OSV.dev
RUSTSEC-2026-0183
May 12, 2026
Potential undefined behavior when calling Remote::list() When calling Fixed in
0.21.0
References Updated Jun 17, 2026 · Source: OSV.dev
GHSA-j39j-6gw9-jw6h
RUSTSEC-2026-0008
Feb 04, 2026
git2 has potential undefined behavior when dereferencing Buf struct
Low
Network
Low
None
None
If the Buf struct is dereferenced immediately after calling new() or default() on the Buf struct, a null pointer is passed to the unsafe function slice::from_raw_parts. According to the safety section documentation of the function, data must be non-null and aligned even for zero-length slices or slices of ZSTs. Thus, passing a null pointer will lead to undefined behavior. Fixed in
0.20.4
References Updated Sep 10, 2026 · Source: OSV.dev |
0.18.0
unknown
Dependencies (10)
+ 2 more |
|
0.17.2
unknown
3 CVEs
RUSTSEC-2026-0184
May 13, 2026
Potential undefined behavior with Signature from a buffer-created BlameHunk When a Fixed in
0.21.0
References Updated Jun 17, 2026 · Source: OSV.dev
RUSTSEC-2026-0183
May 12, 2026
Potential undefined behavior when calling Remote::list() When calling Fixed in
0.21.0
References Updated Jun 17, 2026 · Source: OSV.dev
GHSA-j39j-6gw9-jw6h
RUSTSEC-2026-0008
Feb 04, 2026
git2 has potential undefined behavior when dereferencing Buf struct
Low
Network
Low
None
None
If the Buf struct is dereferenced immediately after calling new() or default() on the Buf struct, a null pointer is passed to the unsafe function slice::from_raw_parts. According to the safety section documentation of the function, data must be non-null and aligned even for zero-length slices or slices of ZSTs. Thus, passing a null pointer will lead to undefined behavior. Fixed in
0.20.4
References Updated Sep 10, 2026 · Source: OSV.dev |
0.17.2
unknown
Dependencies (10)
+ 2 more |
|
0.17.1
unknown
3 CVEs
RUSTSEC-2026-0184
May 13, 2026
Potential undefined behavior with Signature from a buffer-created BlameHunk When a Fixed in
0.21.0
References Updated Jun 17, 2026 · Source: OSV.dev
RUSTSEC-2026-0183
May 12, 2026
Potential undefined behavior when calling Remote::list() When calling Fixed in
0.21.0
References Updated Jun 17, 2026 · Source: OSV.dev
GHSA-j39j-6gw9-jw6h
RUSTSEC-2026-0008
Feb 04, 2026
git2 has potential undefined behavior when dereferencing Buf struct
Low
Network
Low
None
None
If the Buf struct is dereferenced immediately after calling new() or default() on the Buf struct, a null pointer is passed to the unsafe function slice::from_raw_parts. According to the safety section documentation of the function, data must be non-null and aligned even for zero-length slices or slices of ZSTs. Thus, passing a null pointer will lead to undefined behavior. Fixed in
0.20.4
References Updated Sep 10, 2026 · Source: OSV.dev |
0.17.1
unknown
Dependencies (10)
+ 2 more |
|
0.17.0
unknown
3 CVEs
RUSTSEC-2026-0184
May 13, 2026
Potential undefined behavior with Signature from a buffer-created BlameHunk When a Fixed in
0.21.0
References Updated Jun 17, 2026 · Source: OSV.dev
RUSTSEC-2026-0183
May 12, 2026
Potential undefined behavior when calling Remote::list() When calling Fixed in
0.21.0
References Updated Jun 17, 2026 · Source: OSV.dev
GHSA-j39j-6gw9-jw6h
RUSTSEC-2026-0008
Feb 04, 2026
git2 has potential undefined behavior when dereferencing Buf struct
Low
Network
Low
None
None
If the Buf struct is dereferenced immediately after calling new() or default() on the Buf struct, a null pointer is passed to the unsafe function slice::from_raw_parts. According to the safety section documentation of the function, data must be non-null and aligned even for zero-length slices or slices of ZSTs. Thus, passing a null pointer will lead to undefined behavior. Fixed in
0.20.4
References Updated Sep 10, 2026 · Source: OSV.dev |
0.17.0
unknown
Dependencies (10)
+ 2 more |
|
0.16.1
unknown
3 CVEs
RUSTSEC-2026-0184
May 13, 2026
Potential undefined behavior with Signature from a buffer-created BlameHunk When a Fixed in
0.21.0
References Updated Jun 17, 2026 · Source: OSV.dev
RUSTSEC-2026-0183
May 12, 2026
Potential undefined behavior when calling Remote::list() When calling Fixed in
0.21.0
References Updated Jun 17, 2026 · Source: OSV.dev
GHSA-j39j-6gw9-jw6h
RUSTSEC-2026-0008
Feb 04, 2026
git2 has potential undefined behavior when dereferencing Buf struct
Low
Network
Low
None
None
If the Buf struct is dereferenced immediately after calling new() or default() on the Buf struct, a null pointer is passed to the unsafe function slice::from_raw_parts. According to the safety section documentation of the function, data must be non-null and aligned even for zero-length slices or slices of ZSTs. Thus, passing a null pointer will lead to undefined behavior. Fixed in
0.20.4
References Updated Sep 10, 2026 · Source: OSV.dev |
0.16.1
unknown
Dependencies (11)
+ 3 more |
|
0.16.0
unknown
4 CVEs
RUSTSEC-2026-0184
May 13, 2026
Potential undefined behavior with Signature from a buffer-created BlameHunk When a Fixed in
0.21.0
References Updated Jun 17, 2026 · Source: OSV.dev
RUSTSEC-2026-0183
May 12, 2026
Potential undefined behavior when calling Remote::list() When calling Fixed in
0.21.0
References Updated Jun 17, 2026 · Source: OSV.dev
GHSA-j39j-6gw9-jw6h
RUSTSEC-2026-0008
Feb 04, 2026
git2 has potential undefined behavior when dereferencing Buf struct
Low
Network
Low
None
None
If the Buf struct is dereferenced immediately after calling new() or default() on the Buf struct, a null pointer is passed to the unsafe function slice::from_raw_parts. According to the safety section documentation of the function, data must be non-null and aligned even for zero-length slices or slices of ZSTs. Thus, passing a null pointer will lead to undefined behavior. Fixed in
0.20.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-22742
GHSA-m4ch-rfv5-x5g3
GHSA-8643-3wh5-rmjq
RUSTSEC-2023-0003
Jan 20, 2023
git2-rs fails to verify SSH keys by default
6.8
/ 10
Medium
Network
High
None
Required
Unchanged
High
High
None
The git2 and libgit2-sys crates are Rust wrappers around the libgit2 C library. It was discovered that libgit2 1.5.0 and below did not verify SSH host keys when establishing an SSH connection, exposing users of the library to Man-In-the-Middle attacks. The libgit2 team assigned CVE-2023-22742 to this vulnerability. The following versions of the libgit2-sys Rust crate have been released:
A new git2 crate version has also been released, 0.16.1. This version only bumps its libgit2-sys dependency to ensure no vulnerable libgit2-sys versions are used, but contains no code changes: if you update the libgit2-sys version there is no need to also update the git2 crate version. You can learn more about this vulnerability in libgit2's advisory Fixed in
0.16.1
References
Updated Nov 08, 2023 · Source: OSV.dev |
0.16.0
unknown
Dependencies (11)
+ 3 more |
|
0.15.0
unknown
4 CVEs
RUSTSEC-2026-0184
May 13, 2026
Potential undefined behavior with Signature from a buffer-created BlameHunk When a Fixed in
0.21.0
References Updated Jun 17, 2026 · Source: OSV.dev
RUSTSEC-2026-0183
May 12, 2026
Potential undefined behavior when calling Remote::list() When calling Fixed in
0.21.0
References Updated Jun 17, 2026 · Source: OSV.dev
GHSA-j39j-6gw9-jw6h
RUSTSEC-2026-0008
Feb 04, 2026
git2 has potential undefined behavior when dereferencing Buf struct
Low
Network
Low
None
None
If the Buf struct is dereferenced immediately after calling new() or default() on the Buf struct, a null pointer is passed to the unsafe function slice::from_raw_parts. According to the safety section documentation of the function, data must be non-null and aligned even for zero-length slices or slices of ZSTs. Thus, passing a null pointer will lead to undefined behavior. Fixed in
0.20.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-22742
GHSA-m4ch-rfv5-x5g3
GHSA-8643-3wh5-rmjq
RUSTSEC-2023-0003
Jan 20, 2023
git2-rs fails to verify SSH keys by default
6.8
/ 10
Medium
Network
High
None
Required
Unchanged
High
High
None
The git2 and libgit2-sys crates are Rust wrappers around the libgit2 C library. It was discovered that libgit2 1.5.0 and below did not verify SSH host keys when establishing an SSH connection, exposing users of the library to Man-In-the-Middle attacks. The libgit2 team assigned CVE-2023-22742 to this vulnerability. The following versions of the libgit2-sys Rust crate have been released:
A new git2 crate version has also been released, 0.16.1. This version only bumps its libgit2-sys dependency to ensure no vulnerable libgit2-sys versions are used, but contains no code changes: if you update the libgit2-sys version there is no need to also update the git2 crate version. You can learn more about this vulnerability in libgit2's advisory Fixed in
0.16.1
References
Updated Nov 08, 2023 · Source: OSV.dev |
0.15.0
unknown
Dependencies (11)
+ 3 more |
|
0.14.4
unknown
4 CVEs
RUSTSEC-2026-0184
May 13, 2026
Potential undefined behavior with Signature from a buffer-created BlameHunk When a Fixed in
0.21.0
References Updated Jun 17, 2026 · Source: OSV.dev
RUSTSEC-2026-0183
May 12, 2026
Potential undefined behavior when calling Remote::list() When calling Fixed in
0.21.0
References Updated Jun 17, 2026 · Source: OSV.dev
GHSA-j39j-6gw9-jw6h
RUSTSEC-2026-0008
Feb 04, 2026
git2 has potential undefined behavior when dereferencing Buf struct
Low
Network
Low
None
None
If the Buf struct is dereferenced immediately after calling new() or default() on the Buf struct, a null pointer is passed to the unsafe function slice::from_raw_parts. According to the safety section documentation of the function, data must be non-null and aligned even for zero-length slices or slices of ZSTs. Thus, passing a null pointer will lead to undefined behavior. Fixed in
0.20.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-22742
GHSA-m4ch-rfv5-x5g3
GHSA-8643-3wh5-rmjq
RUSTSEC-2023-0003
Jan 20, 2023
git2-rs fails to verify SSH keys by default
6.8
/ 10
Medium
Network
High
None
Required
Unchanged
High
High
None
The git2 and libgit2-sys crates are Rust wrappers around the libgit2 C library. It was discovered that libgit2 1.5.0 and below did not verify SSH host keys when establishing an SSH connection, exposing users of the library to Man-In-the-Middle attacks. The libgit2 team assigned CVE-2023-22742 to this vulnerability. The following versions of the libgit2-sys Rust crate have been released:
A new git2 crate version has also been released, 0.16.1. This version only bumps its libgit2-sys dependency to ensure no vulnerable libgit2-sys versions are used, but contains no code changes: if you update the libgit2-sys version there is no need to also update the git2 crate version. You can learn more about this vulnerability in libgit2's advisory Fixed in
0.16.1
References
Updated Nov 08, 2023 · Source: OSV.dev |
0.14.4
unknown
Dependencies (11)
+ 3 more |
|
0.14.3
unknown
4 CVEs
RUSTSEC-2026-0184
May 13, 2026
Potential undefined behavior with Signature from a buffer-created BlameHunk When a Fixed in
0.21.0
References Updated Jun 17, 2026 · Source: OSV.dev
RUSTSEC-2026-0183
May 12, 2026
Potential undefined behavior when calling Remote::list() When calling Fixed in
0.21.0
References Updated Jun 17, 2026 · Source: OSV.dev
GHSA-j39j-6gw9-jw6h
RUSTSEC-2026-0008
Feb 04, 2026
git2 has potential undefined behavior when dereferencing Buf struct
Low
Network
Low
None
None
If the Buf struct is dereferenced immediately after calling new() or default() on the Buf struct, a null pointer is passed to the unsafe function slice::from_raw_parts. According to the safety section documentation of the function, data must be non-null and aligned even for zero-length slices or slices of ZSTs. Thus, passing a null pointer will lead to undefined behavior. Fixed in
0.20.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-22742
GHSA-m4ch-rfv5-x5g3
GHSA-8643-3wh5-rmjq
RUSTSEC-2023-0003
Jan 20, 2023
git2-rs fails to verify SSH keys by default
6.8
/ 10
Medium
Network
High
None
Required
Unchanged
High
High
None
The git2 and libgit2-sys crates are Rust wrappers around the libgit2 C library. It was discovered that libgit2 1.5.0 and below did not verify SSH host keys when establishing an SSH connection, exposing users of the library to Man-In-the-Middle attacks. The libgit2 team assigned CVE-2023-22742 to this vulnerability. The following versions of the libgit2-sys Rust crate have been released:
A new git2 crate version has also been released, 0.16.1. This version only bumps its libgit2-sys dependency to ensure no vulnerable libgit2-sys versions are used, but contains no code changes: if you update the libgit2-sys version there is no need to also update the git2 crate version. You can learn more about this vulnerability in libgit2's advisory Fixed in
0.16.1
References
Updated Nov 08, 2023 · Source: OSV.dev |
0.14.3
unknown
Dependencies (11)
+ 3 more |
|
0.14.2
unknown
4 CVEs
RUSTSEC-2026-0184
May 13, 2026
Potential undefined behavior with Signature from a buffer-created BlameHunk When a Fixed in
0.21.0
References Updated Jun 17, 2026 · Source: OSV.dev
RUSTSEC-2026-0183
May 12, 2026
Potential undefined behavior when calling Remote::list() When calling Fixed in
0.21.0
References Updated Jun 17, 2026 · Source: OSV.dev
GHSA-j39j-6gw9-jw6h
RUSTSEC-2026-0008
Feb 04, 2026
git2 has potential undefined behavior when dereferencing Buf struct
Low
Network
Low
None
None
If the Buf struct is dereferenced immediately after calling new() or default() on the Buf struct, a null pointer is passed to the unsafe function slice::from_raw_parts. According to the safety section documentation of the function, data must be non-null and aligned even for zero-length slices or slices of ZSTs. Thus, passing a null pointer will lead to undefined behavior. Fixed in
0.20.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-22742
GHSA-m4ch-rfv5-x5g3
GHSA-8643-3wh5-rmjq
RUSTSEC-2023-0003
Jan 20, 2023
git2-rs fails to verify SSH keys by default
6.8
/ 10
Medium
Network
High
None
Required
Unchanged
High
High
None
The git2 and libgit2-sys crates are Rust wrappers around the libgit2 C library. It was discovered that libgit2 1.5.0 and below did not verify SSH host keys when establishing an SSH connection, exposing users of the library to Man-In-the-Middle attacks. The libgit2 team assigned CVE-2023-22742 to this vulnerability. The following versions of the libgit2-sys Rust crate have been released:
A new git2 crate version has also been released, 0.16.1. This version only bumps its libgit2-sys dependency to ensure no vulnerable libgit2-sys versions are used, but contains no code changes: if you update the libgit2-sys version there is no need to also update the git2 crate version. You can learn more about this vulnerability in libgit2's advisory Fixed in
0.16.1
References
Updated Nov 08, 2023 · Source: OSV.dev |
0.14.2
unknown
Dependencies (11)
+ 3 more |
|
0.14.1
unknown
4 CVEs
RUSTSEC-2026-0184
May 13, 2026
Potential undefined behavior with Signature from a buffer-created BlameHunk When a Fixed in
0.21.0
References Updated Jun 17, 2026 · Source: OSV.dev
RUSTSEC-2026-0183
May 12, 2026
Potential undefined behavior when calling Remote::list() When calling Fixed in
0.21.0
References Updated Jun 17, 2026 · Source: OSV.dev
GHSA-j39j-6gw9-jw6h
RUSTSEC-2026-0008
Feb 04, 2026
git2 has potential undefined behavior when dereferencing Buf struct
Low
Network
Low
None
None
If the Buf struct is dereferenced immediately after calling new() or default() on the Buf struct, a null pointer is passed to the unsafe function slice::from_raw_parts. According to the safety section documentation of the function, data must be non-null and aligned even for zero-length slices or slices of ZSTs. Thus, passing a null pointer will lead to undefined behavior. Fixed in
0.20.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-22742
GHSA-m4ch-rfv5-x5g3
GHSA-8643-3wh5-rmjq
RUSTSEC-2023-0003
Jan 20, 2023
git2-rs fails to verify SSH keys by default
6.8
/ 10
Medium
Network
High
None
Required
Unchanged
High
High
None
The git2 and libgit2-sys crates are Rust wrappers around the libgit2 C library. It was discovered that libgit2 1.5.0 and below did not verify SSH host keys when establishing an SSH connection, exposing users of the library to Man-In-the-Middle attacks. The libgit2 team assigned CVE-2023-22742 to this vulnerability. The following versions of the libgit2-sys Rust crate have been released:
A new git2 crate version has also been released, 0.16.1. This version only bumps its libgit2-sys dependency to ensure no vulnerable libgit2-sys versions are used, but contains no code changes: if you update the libgit2-sys version there is no need to also update the git2 crate version. You can learn more about this vulnerability in libgit2's advisory Fixed in
0.16.1
References
Updated Nov 08, 2023 · Source: OSV.dev |
0.14.1
unknown
Dependencies (11)
+ 3 more |
|
0.14.0
unknown
4 CVEs
RUSTSEC-2026-0184
May 13, 2026
Potential undefined behavior with Signature from a buffer-created BlameHunk When a Fixed in
0.21.0
References Updated Jun 17, 2026 · Source: OSV.dev
RUSTSEC-2026-0183
May 12, 2026
Potential undefined behavior when calling Remote::list() When calling Fixed in
0.21.0
References Updated Jun 17, 2026 · Source: OSV.dev
GHSA-j39j-6gw9-jw6h
RUSTSEC-2026-0008
Feb 04, 2026
git2 has potential undefined behavior when dereferencing Buf struct
Low
Network
Low
None
None
If the Buf struct is dereferenced immediately after calling new() or default() on the Buf struct, a null pointer is passed to the unsafe function slice::from_raw_parts. According to the safety section documentation of the function, data must be non-null and aligned even for zero-length slices or slices of ZSTs. Thus, passing a null pointer will lead to undefined behavior. Fixed in
0.20.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-22742
GHSA-m4ch-rfv5-x5g3
GHSA-8643-3wh5-rmjq
RUSTSEC-2023-0003
Jan 20, 2023
git2-rs fails to verify SSH keys by default
6.8
/ 10
Medium
Network
High
None
Required
Unchanged
High
High
None
The git2 and libgit2-sys crates are Rust wrappers around the libgit2 C library. It was discovered that libgit2 1.5.0 and below did not verify SSH host keys when establishing an SSH connection, exposing users of the library to Man-In-the-Middle attacks. The libgit2 team assigned CVE-2023-22742 to this vulnerability. The following versions of the libgit2-sys Rust crate have been released:
A new git2 crate version has also been released, 0.16.1. This version only bumps its libgit2-sys dependency to ensure no vulnerable libgit2-sys versions are used, but contains no code changes: if you update the libgit2-sys version there is no need to also update the git2 crate version. You can learn more about this vulnerability in libgit2's advisory Fixed in
0.16.1
References
Updated Nov 08, 2023 · Source: OSV.dev |
0.14.0
unknown
Dependencies (11)
+ 3 more |
|
0.13.25
unknown
4 CVEs
RUSTSEC-2026-0184
May 13, 2026
Potential undefined behavior with Signature from a buffer-created BlameHunk When a Fixed in
0.21.0
References Updated Jun 17, 2026 · Source: OSV.dev
RUSTSEC-2026-0183
May 12, 2026
Potential undefined behavior when calling Remote::list() When calling Fixed in
0.21.0
References Updated Jun 17, 2026 · Source: OSV.dev
GHSA-j39j-6gw9-jw6h
RUSTSEC-2026-0008
Feb 04, 2026
git2 has potential undefined behavior when dereferencing Buf struct
Low
Network
Low
None
None
If the Buf struct is dereferenced immediately after calling new() or default() on the Buf struct, a null pointer is passed to the unsafe function slice::from_raw_parts. According to the safety section documentation of the function, data must be non-null and aligned even for zero-length slices or slices of ZSTs. Thus, passing a null pointer will lead to undefined behavior. Fixed in
0.20.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-22742
GHSA-m4ch-rfv5-x5g3
GHSA-8643-3wh5-rmjq
RUSTSEC-2023-0003
Jan 20, 2023
git2-rs fails to verify SSH keys by default
6.8
/ 10
Medium
Network
High
None
Required
Unchanged
High
High
None
The git2 and libgit2-sys crates are Rust wrappers around the libgit2 C library. It was discovered that libgit2 1.5.0 and below did not verify SSH host keys when establishing an SSH connection, exposing users of the library to Man-In-the-Middle attacks. The libgit2 team assigned CVE-2023-22742 to this vulnerability. The following versions of the libgit2-sys Rust crate have been released:
A new git2 crate version has also been released, 0.16.1. This version only bumps its libgit2-sys dependency to ensure no vulnerable libgit2-sys versions are used, but contains no code changes: if you update the libgit2-sys version there is no need to also update the git2 crate version. You can learn more about this vulnerability in libgit2's advisory Fixed in
0.16.1
References
Updated Nov 08, 2023 · Source: OSV.dev |
0.13.25
unknown
Dependencies (11)
+ 3 more |
|
0.13.24
unknown
4 CVEs
RUSTSEC-2026-0184
May 13, 2026
Potential undefined behavior with Signature from a buffer-created BlameHunk When a Fixed in
0.21.0
References Updated Jun 17, 2026 · Source: OSV.dev
RUSTSEC-2026-0183
May 12, 2026
Potential undefined behavior when calling Remote::list() When calling Fixed in
0.21.0
References Updated Jun 17, 2026 · Source: OSV.dev
GHSA-j39j-6gw9-jw6h
RUSTSEC-2026-0008
Feb 04, 2026
git2 has potential undefined behavior when dereferencing Buf struct
Low
Network
Low
None
None
If the Buf struct is dereferenced immediately after calling new() or default() on the Buf struct, a null pointer is passed to the unsafe function slice::from_raw_parts. According to the safety section documentation of the function, data must be non-null and aligned even for zero-length slices or slices of ZSTs. Thus, passing a null pointer will lead to undefined behavior. Fixed in
0.20.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-22742
GHSA-m4ch-rfv5-x5g3
GHSA-8643-3wh5-rmjq
RUSTSEC-2023-0003
Jan 20, 2023
git2-rs fails to verify SSH keys by default
6.8
/ 10
Medium
Network
High
None
Required
Unchanged
High
High
None
The git2 and libgit2-sys crates are Rust wrappers around the libgit2 C library. It was discovered that libgit2 1.5.0 and below did not verify SSH host keys when establishing an SSH connection, exposing users of the library to Man-In-the-Middle attacks. The libgit2 team assigned CVE-2023-22742 to this vulnerability. The following versions of the libgit2-sys Rust crate have been released:
A new git2 crate version has also been released, 0.16.1. This version only bumps its libgit2-sys dependency to ensure no vulnerable libgit2-sys versions are used, but contains no code changes: if you update the libgit2-sys version there is no need to also update the git2 crate version. You can learn more about this vulnerability in libgit2's advisory Fixed in
0.16.1
References
Updated Nov 08, 2023 · Source: OSV.dev |
0.13.24
unknown
Dependencies (12)
+ 4 more |
|
0.13.23
unknown
4 CVEs
RUSTSEC-2026-0184
May 13, 2026
Potential undefined behavior with Signature from a buffer-created BlameHunk When a Fixed in
0.21.0
References Updated Jun 17, 2026 · Source: OSV.dev
RUSTSEC-2026-0183
May 12, 2026
Potential undefined behavior when calling Remote::list() When calling Fixed in
0.21.0
References Updated Jun 17, 2026 · Source: OSV.dev
GHSA-j39j-6gw9-jw6h
RUSTSEC-2026-0008
Feb 04, 2026
git2 has potential undefined behavior when dereferencing Buf struct
Low
Network
Low
None
None
If the Buf struct is dereferenced immediately after calling new() or default() on the Buf struct, a null pointer is passed to the unsafe function slice::from_raw_parts. According to the safety section documentation of the function, data must be non-null and aligned even for zero-length slices or slices of ZSTs. Thus, passing a null pointer will lead to undefined behavior. Fixed in
0.20.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-22742
GHSA-m4ch-rfv5-x5g3
GHSA-8643-3wh5-rmjq
RUSTSEC-2023-0003
Jan 20, 2023
git2-rs fails to verify SSH keys by default
6.8
/ 10
Medium
Network
High
None
Required
Unchanged
High
High
None
The git2 and libgit2-sys crates are Rust wrappers around the libgit2 C library. It was discovered that libgit2 1.5.0 and below did not verify SSH host keys when establishing an SSH connection, exposing users of the library to Man-In-the-Middle attacks. The libgit2 team assigned CVE-2023-22742 to this vulnerability. The following versions of the libgit2-sys Rust crate have been released:
A new git2 crate version has also been released, 0.16.1. This version only bumps its libgit2-sys dependency to ensure no vulnerable libgit2-sys versions are used, but contains no code changes: if you update the libgit2-sys version there is no need to also update the git2 crate version. You can learn more about this vulnerability in libgit2's advisory Fixed in
0.16.1
References
Updated Nov 08, 2023 · Source: OSV.dev |
0.13.23
unknown
Dependencies (12)
+ 4 more |
|
0.13.22
unknown
4 CVEs
RUSTSEC-2026-0184
May 13, 2026
Potential undefined behavior with Signature from a buffer-created BlameHunk When a Fixed in
0.21.0
References Updated Jun 17, 2026 · Source: OSV.dev
RUSTSEC-2026-0183
May 12, 2026
Potential undefined behavior when calling Remote::list() When calling Fixed in
0.21.0
References Updated Jun 17, 2026 · Source: OSV.dev
GHSA-j39j-6gw9-jw6h
RUSTSEC-2026-0008
Feb 04, 2026
git2 has potential undefined behavior when dereferencing Buf struct
Low
Network
Low
None
None
If the Buf struct is dereferenced immediately after calling new() or default() on the Buf struct, a null pointer is passed to the unsafe function slice::from_raw_parts. According to the safety section documentation of the function, data must be non-null and aligned even for zero-length slices or slices of ZSTs. Thus, passing a null pointer will lead to undefined behavior. Fixed in
0.20.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-22742
GHSA-m4ch-rfv5-x5g3
GHSA-8643-3wh5-rmjq
RUSTSEC-2023-0003
Jan 20, 2023
git2-rs fails to verify SSH keys by default
6.8
/ 10
Medium
Network
High
None
Required
Unchanged
High
High
None
The git2 and libgit2-sys crates are Rust wrappers around the libgit2 C library. It was discovered that libgit2 1.5.0 and below did not verify SSH host keys when establishing an SSH connection, exposing users of the library to Man-In-the-Middle attacks. The libgit2 team assigned CVE-2023-22742 to this vulnerability. The following versions of the libgit2-sys Rust crate have been released:
A new git2 crate version has also been released, 0.16.1. This version only bumps its libgit2-sys dependency to ensure no vulnerable libgit2-sys versions are used, but contains no code changes: if you update the libgit2-sys version there is no need to also update the git2 crate version. You can learn more about this vulnerability in libgit2's advisory Fixed in
0.16.1
References
Updated Nov 08, 2023 · Source: OSV.dev |
0.13.22
unknown
Dependencies (12)
+ 4 more |
|
0.13.21
unknown
4 CVEs
RUSTSEC-2026-0184
May 13, 2026
Potential undefined behavior with Signature from a buffer-created BlameHunk When a Fixed in
0.21.0
References Updated Jun 17, 2026 · Source: OSV.dev
RUSTSEC-2026-0183
May 12, 2026
Potential undefined behavior when calling Remote::list() When calling Fixed in
0.21.0
References Updated Jun 17, 2026 · Source: OSV.dev
GHSA-j39j-6gw9-jw6h
RUSTSEC-2026-0008
Feb 04, 2026
git2 has potential undefined behavior when dereferencing Buf struct
Low
Network
Low
None
None
If the Buf struct is dereferenced immediately after calling new() or default() on the Buf struct, a null pointer is passed to the unsafe function slice::from_raw_parts. According to the safety section documentation of the function, data must be non-null and aligned even for zero-length slices or slices of ZSTs. Thus, passing a null pointer will lead to undefined behavior. Fixed in
0.20.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-22742
GHSA-m4ch-rfv5-x5g3
GHSA-8643-3wh5-rmjq
RUSTSEC-2023-0003
Jan 20, 2023
git2-rs fails to verify SSH keys by default
6.8
/ 10
Medium
Network
High
None
Required
Unchanged
High
High
None
The git2 and libgit2-sys crates are Rust wrappers around the libgit2 C library. It was discovered that libgit2 1.5.0 and below did not verify SSH host keys when establishing an SSH connection, exposing users of the library to Man-In-the-Middle attacks. The libgit2 team assigned CVE-2023-22742 to this vulnerability. The following versions of the libgit2-sys Rust crate have been released:
A new git2 crate version has also been released, 0.16.1. This version only bumps its libgit2-sys dependency to ensure no vulnerable libgit2-sys versions are used, but contains no code changes: if you update the libgit2-sys version there is no need to also update the git2 crate version. You can learn more about this vulnerability in libgit2's advisory Fixed in
0.16.1
References
Updated Nov 08, 2023 · Source: OSV.dev |
0.13.21
unknown
Dependencies (12)
+ 4 more |
|
0.13.20
unknown
4 CVEs
RUSTSEC-2026-0184
May 13, 2026
Potential undefined behavior with Signature from a buffer-created BlameHunk When a Fixed in
0.21.0
References Updated Jun 17, 2026 · Source: OSV.dev
RUSTSEC-2026-0183
May 12, 2026
Potential undefined behavior when calling Remote::list() When calling Fixed in
0.21.0
References Updated Jun 17, 2026 · Source: OSV.dev
GHSA-j39j-6gw9-jw6h
RUSTSEC-2026-0008
Feb 04, 2026
git2 has potential undefined behavior when dereferencing Buf struct
Low
Network
Low
None
None
If the Buf struct is dereferenced immediately after calling new() or default() on the Buf struct, a null pointer is passed to the unsafe function slice::from_raw_parts. According to the safety section documentation of the function, data must be non-null and aligned even for zero-length slices or slices of ZSTs. Thus, passing a null pointer will lead to undefined behavior. Fixed in
0.20.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-22742
GHSA-m4ch-rfv5-x5g3
GHSA-8643-3wh5-rmjq
RUSTSEC-2023-0003
Jan 20, 2023
git2-rs fails to verify SSH keys by default
6.8
/ 10
Medium
Network
High
None
Required
Unchanged
High
High
None
The git2 and libgit2-sys crates are Rust wrappers around the libgit2 C library. It was discovered that libgit2 1.5.0 and below did not verify SSH host keys when establishing an SSH connection, exposing users of the library to Man-In-the-Middle attacks. The libgit2 team assigned CVE-2023-22742 to this vulnerability. The following versions of the libgit2-sys Rust crate have been released:
A new git2 crate version has also been released, 0.16.1. This version only bumps its libgit2-sys dependency to ensure no vulnerable libgit2-sys versions are used, but contains no code changes: if you update the libgit2-sys version there is no need to also update the git2 crate version. You can learn more about this vulnerability in libgit2's advisory Fixed in
0.16.1
References
Updated Nov 08, 2023 · Source: OSV.dev |
0.13.20
unknown
Dependencies (12)
+ 4 more |
|
0.13.19
unknown
4 CVEs
RUSTSEC-2026-0184
May 13, 2026
Potential undefined behavior with Signature from a buffer-created BlameHunk When a Fixed in
0.21.0
References Updated Jun 17, 2026 · Source: OSV.dev
RUSTSEC-2026-0183
May 12, 2026
Potential undefined behavior when calling Remote::list() When calling Fixed in
0.21.0
References Updated Jun 17, 2026 · Source: OSV.dev
GHSA-j39j-6gw9-jw6h
RUSTSEC-2026-0008
Feb 04, 2026
git2 has potential undefined behavior when dereferencing Buf struct
Low
Network
Low
None
None
If the Buf struct is dereferenced immediately after calling new() or default() on the Buf struct, a null pointer is passed to the unsafe function slice::from_raw_parts. According to the safety section documentation of the function, data must be non-null and aligned even for zero-length slices or slices of ZSTs. Thus, passing a null pointer will lead to undefined behavior. Fixed in
0.20.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-22742
GHSA-m4ch-rfv5-x5g3
GHSA-8643-3wh5-rmjq
RUSTSEC-2023-0003
Jan 20, 2023
git2-rs fails to verify SSH keys by default
6.8
/ 10
Medium
Network
High
None
Required
Unchanged
High
High
None
The git2 and libgit2-sys crates are Rust wrappers around the libgit2 C library. It was discovered that libgit2 1.5.0 and below did not verify SSH host keys when establishing an SSH connection, exposing users of the library to Man-In-the-Middle attacks. The libgit2 team assigned CVE-2023-22742 to this vulnerability. The following versions of the libgit2-sys Rust crate have been released:
A new git2 crate version has also been released, 0.16.1. This version only bumps its libgit2-sys dependency to ensure no vulnerable libgit2-sys versions are used, but contains no code changes: if you update the libgit2-sys version there is no need to also update the git2 crate version. You can learn more about this vulnerability in libgit2's advisory Fixed in
0.16.1
References
Updated Nov 08, 2023 · Source: OSV.dev |
0.13.19
unknown
Dependencies (12)
+ 4 more |
|
0.13.18
unknown
4 CVEs
RUSTSEC-2026-0184
May 13, 2026
Potential undefined behavior with Signature from a buffer-created BlameHunk When a Fixed in
0.21.0
References Updated Jun 17, 2026 · Source: OSV.dev
RUSTSEC-2026-0183
May 12, 2026
Potential undefined behavior when calling Remote::list() When calling Fixed in
0.21.0
References Updated Jun 17, 2026 · Source: OSV.dev
GHSA-j39j-6gw9-jw6h
RUSTSEC-2026-0008
Feb 04, 2026
git2 has potential undefined behavior when dereferencing Buf struct
Low
Network
Low
None
None
If the Buf struct is dereferenced immediately after calling new() or default() on the Buf struct, a null pointer is passed to the unsafe function slice::from_raw_parts. According to the safety section documentation of the function, data must be non-null and aligned even for zero-length slices or slices of ZSTs. Thus, passing a null pointer will lead to undefined behavior. Fixed in
0.20.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-22742
GHSA-m4ch-rfv5-x5g3
GHSA-8643-3wh5-rmjq
RUSTSEC-2023-0003
Jan 20, 2023
git2-rs fails to verify SSH keys by default
6.8
/ 10
Medium
Network
High
None
Required
Unchanged
High
High
None
The git2 and libgit2-sys crates are Rust wrappers around the libgit2 C library. It was discovered that libgit2 1.5.0 and below did not verify SSH host keys when establishing an SSH connection, exposing users of the library to Man-In-the-Middle attacks. The libgit2 team assigned CVE-2023-22742 to this vulnerability. The following versions of the libgit2-sys Rust crate have been released:
A new git2 crate version has also been released, 0.16.1. This version only bumps its libgit2-sys dependency to ensure no vulnerable libgit2-sys versions are used, but contains no code changes: if you update the libgit2-sys version there is no need to also update the git2 crate version. You can learn more about this vulnerability in libgit2's advisory Fixed in
0.16.1
References
Updated Nov 08, 2023 · Source: OSV.dev |
0.13.18
unknown
Dependencies (12)
+ 4 more |
|
0.13.17
unknown
4 CVEs
RUSTSEC-2026-0184
May 13, 2026
Potential undefined behavior with Signature from a buffer-created BlameHunk When a Fixed in
0.21.0
References Updated Jun 17, 2026 · Source: OSV.dev
RUSTSEC-2026-0183
May 12, 2026
Potential undefined behavior when calling Remote::list() When calling Fixed in
0.21.0
References Updated Jun 17, 2026 · Source: OSV.dev
GHSA-j39j-6gw9-jw6h
RUSTSEC-2026-0008
Feb 04, 2026
git2 has potential undefined behavior when dereferencing Buf struct
Low
Network
Low
None
None
If the Buf struct is dereferenced immediately after calling new() or default() on the Buf struct, a null pointer is passed to the unsafe function slice::from_raw_parts. According to the safety section documentation of the function, data must be non-null and aligned even for zero-length slices or slices of ZSTs. Thus, passing a null pointer will lead to undefined behavior. Fixed in
0.20.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-22742
GHSA-m4ch-rfv5-x5g3
GHSA-8643-3wh5-rmjq
RUSTSEC-2023-0003
Jan 20, 2023
git2-rs fails to verify SSH keys by default
6.8
/ 10
Medium
Network
High
None
Required
Unchanged
High
High
None
The git2 and libgit2-sys crates are Rust wrappers around the libgit2 C library. It was discovered that libgit2 1.5.0 and below did not verify SSH host keys when establishing an SSH connection, exposing users of the library to Man-In-the-Middle attacks. The libgit2 team assigned CVE-2023-22742 to this vulnerability. The following versions of the libgit2-sys Rust crate have been released:
A new git2 crate version has also been released, 0.16.1. This version only bumps its libgit2-sys dependency to ensure no vulnerable libgit2-sys versions are used, but contains no code changes: if you update the libgit2-sys version there is no need to also update the git2 crate version. You can learn more about this vulnerability in libgit2's advisory Fixed in
0.16.1
References
Updated Nov 08, 2023 · Source: OSV.dev |
0.13.17
unknown
Dependencies (12)
+ 4 more |
|
0.13.16
unknown
4 CVEs
RUSTSEC-2026-0184
May 13, 2026
Potential undefined behavior with Signature from a buffer-created BlameHunk When a Fixed in
0.21.0
References Updated Jun 17, 2026 · Source: OSV.dev
RUSTSEC-2026-0183
May 12, 2026
Potential undefined behavior when calling Remote::list() When calling Fixed in
0.21.0
References Updated Jun 17, 2026 · Source: OSV.dev
GHSA-j39j-6gw9-jw6h
RUSTSEC-2026-0008
Feb 04, 2026
git2 has potential undefined behavior when dereferencing Buf struct
Low
Network
Low
None
None
If the Buf struct is dereferenced immediately after calling new() or default() on the Buf struct, a null pointer is passed to the unsafe function slice::from_raw_parts. According to the safety section documentation of the function, data must be non-null and aligned even for zero-length slices or slices of ZSTs. Thus, passing a null pointer will lead to undefined behavior. Fixed in
0.20.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-22742
GHSA-m4ch-rfv5-x5g3
GHSA-8643-3wh5-rmjq
RUSTSEC-2023-0003
Jan 20, 2023
git2-rs fails to verify SSH keys by default
6.8
/ 10
Medium
Network
High
None
Required
Unchanged
High
High
None
The git2 and libgit2-sys crates are Rust wrappers around the libgit2 C library. It was discovered that libgit2 1.5.0 and below did not verify SSH host keys when establishing an SSH connection, exposing users of the library to Man-In-the-Middle attacks. The libgit2 team assigned CVE-2023-22742 to this vulnerability. The following versions of the libgit2-sys Rust crate have been released:
A new git2 crate version has also been released, 0.16.1. This version only bumps its libgit2-sys dependency to ensure no vulnerable libgit2-sys versions are used, but contains no code changes: if you update the libgit2-sys version there is no need to also update the git2 crate version. You can learn more about this vulnerability in libgit2's advisory Fixed in
0.16.1
References
Updated Nov 08, 2023 · Source: OSV.dev |
0.13.16
unknown
Dependencies (12)
+ 4 more |
|
0.13.15
unknown
4 CVEs
RUSTSEC-2026-0184
May 13, 2026
Potential undefined behavior with Signature from a buffer-created BlameHunk When a Fixed in
0.21.0
References Updated Jun 17, 2026 · Source: OSV.dev
RUSTSEC-2026-0183
May 12, 2026
Potential undefined behavior when calling Remote::list() When calling Fixed in
0.21.0
References Updated Jun 17, 2026 · Source: OSV.dev
GHSA-j39j-6gw9-jw6h
RUSTSEC-2026-0008
Feb 04, 2026
git2 has potential undefined behavior when dereferencing Buf struct
Low
Network
Low
None
None
If the Buf struct is dereferenced immediately after calling new() or default() on the Buf struct, a null pointer is passed to the unsafe function slice::from_raw_parts. According to the safety section documentation of the function, data must be non-null and aligned even for zero-length slices or slices of ZSTs. Thus, passing a null pointer will lead to undefined behavior. Fixed in
0.20.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-22742
GHSA-m4ch-rfv5-x5g3
GHSA-8643-3wh5-rmjq
RUSTSEC-2023-0003
Jan 20, 2023
git2-rs fails to verify SSH keys by default
6.8
/ 10
Medium
Network
High
None
Required
Unchanged
High
High
None
The git2 and libgit2-sys crates are Rust wrappers around the libgit2 C library. It was discovered that libgit2 1.5.0 and below did not verify SSH host keys when establishing an SSH connection, exposing users of the library to Man-In-the-Middle attacks. The libgit2 team assigned CVE-2023-22742 to this vulnerability. The following versions of the libgit2-sys Rust crate have been released:
A new git2 crate version has also been released, 0.16.1. This version only bumps its libgit2-sys dependency to ensure no vulnerable libgit2-sys versions are used, but contains no code changes: if you update the libgit2-sys version there is no need to also update the git2 crate version. You can learn more about this vulnerability in libgit2's advisory Fixed in
0.16.1
References
Updated Nov 08, 2023 · Source: OSV.dev |
0.13.15
unknown
Dependencies (12)
+ 4 more |
|
0.13.14
unknown
4 CVEs
RUSTSEC-2026-0184
May 13, 2026
Potential undefined behavior with Signature from a buffer-created BlameHunk When a Fixed in
0.21.0
References Updated Jun 17, 2026 · Source: OSV.dev
RUSTSEC-2026-0183
May 12, 2026
Potential undefined behavior when calling Remote::list() When calling Fixed in
0.21.0
References Updated Jun 17, 2026 · Source: OSV.dev
GHSA-j39j-6gw9-jw6h
RUSTSEC-2026-0008
Feb 04, 2026
git2 has potential undefined behavior when dereferencing Buf struct
Low
Network
Low
None
None
If the Buf struct is dereferenced immediately after calling new() or default() on the Buf struct, a null pointer is passed to the unsafe function slice::from_raw_parts. According to the safety section documentation of the function, data must be non-null and aligned even for zero-length slices or slices of ZSTs. Thus, passing a null pointer will lead to undefined behavior. Fixed in
0.20.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-22742
GHSA-m4ch-rfv5-x5g3
GHSA-8643-3wh5-rmjq
RUSTSEC-2023-0003
Jan 20, 2023
git2-rs fails to verify SSH keys by default
6.8
/ 10
Medium
Network
High
None
Required
Unchanged
High
High
None
The git2 and libgit2-sys crates are Rust wrappers around the libgit2 C library. It was discovered that libgit2 1.5.0 and below did not verify SSH host keys when establishing an SSH connection, exposing users of the library to Man-In-the-Middle attacks. The libgit2 team assigned CVE-2023-22742 to this vulnerability. The following versions of the libgit2-sys Rust crate have been released:
A new git2 crate version has also been released, 0.16.1. This version only bumps its libgit2-sys dependency to ensure no vulnerable libgit2-sys versions are used, but contains no code changes: if you update the libgit2-sys version there is no need to also update the git2 crate version. You can learn more about this vulnerability in libgit2's advisory Fixed in
0.16.1
References
Updated Nov 08, 2023 · Source: OSV.dev |
0.13.14
unknown
Dependencies (12)
+ 4 more |
|
0.13.13
unknown
4 CVEs
RUSTSEC-2026-0184
May 13, 2026
Potential undefined behavior with Signature from a buffer-created BlameHunk When a Fixed in
0.21.0
References Updated Jun 17, 2026 · Source: OSV.dev
RUSTSEC-2026-0183
May 12, 2026
Potential undefined behavior when calling Remote::list() When calling Fixed in
0.21.0
References Updated Jun 17, 2026 · Source: OSV.dev
GHSA-j39j-6gw9-jw6h
RUSTSEC-2026-0008
Feb 04, 2026
git2 has potential undefined behavior when dereferencing Buf struct
Low
Network
Low
None
None
If the Buf struct is dereferenced immediately after calling new() or default() on the Buf struct, a null pointer is passed to the unsafe function slice::from_raw_parts. According to the safety section documentation of the function, data must be non-null and aligned even for zero-length slices or slices of ZSTs. Thus, passing a null pointer will lead to undefined behavior. Fixed in
0.20.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-22742
GHSA-m4ch-rfv5-x5g3
GHSA-8643-3wh5-rmjq
RUSTSEC-2023-0003
Jan 20, 2023
git2-rs fails to verify SSH keys by default
6.8
/ 10
Medium
Network
High
None
Required
Unchanged
High
High
None
The git2 and libgit2-sys crates are Rust wrappers around the libgit2 C library. It was discovered that libgit2 1.5.0 and below did not verify SSH host keys when establishing an SSH connection, exposing users of the library to Man-In-the-Middle attacks. The libgit2 team assigned CVE-2023-22742 to this vulnerability. The following versions of the libgit2-sys Rust crate have been released:
A new git2 crate version has also been released, 0.16.1. This version only bumps its libgit2-sys dependency to ensure no vulnerable libgit2-sys versions are used, but contains no code changes: if you update the libgit2-sys version there is no need to also update the git2 crate version. You can learn more about this vulnerability in libgit2's advisory Fixed in
0.16.1
References
Updated Nov 08, 2023 · Source: OSV.dev |
0.13.13
unknown
Dependencies (12)
+ 4 more |
|
0.13.12
unknown
4 CVEs
RUSTSEC-2026-0184
May 13, 2026
Potential undefined behavior with Signature from a buffer-created BlameHunk When a Fixed in
0.21.0
References Updated Jun 17, 2026 · Source: OSV.dev
RUSTSEC-2026-0183
May 12, 2026
Potential undefined behavior when calling Remote::list() When calling Fixed in
0.21.0
References Updated Jun 17, 2026 · Source: OSV.dev
GHSA-j39j-6gw9-jw6h
RUSTSEC-2026-0008
Feb 04, 2026
git2 has potential undefined behavior when dereferencing Buf struct
Low
Network
Low
None
None
If the Buf struct is dereferenced immediately after calling new() or default() on the Buf struct, a null pointer is passed to the unsafe function slice::from_raw_parts. According to the safety section documentation of the function, data must be non-null and aligned even for zero-length slices or slices of ZSTs. Thus, passing a null pointer will lead to undefined behavior. Fixed in
0.20.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-22742
GHSA-m4ch-rfv5-x5g3
GHSA-8643-3wh5-rmjq
RUSTSEC-2023-0003
Jan 20, 2023
git2-rs fails to verify SSH keys by default
6.8
/ 10
Medium
Network
High
None
Required
Unchanged
High
High
None
The git2 and libgit2-sys crates are Rust wrappers around the libgit2 C library. It was discovered that libgit2 1.5.0 and below did not verify SSH host keys when establishing an SSH connection, exposing users of the library to Man-In-the-Middle attacks. The libgit2 team assigned CVE-2023-22742 to this vulnerability. The following versions of the libgit2-sys Rust crate have been released:
A new git2 crate version has also been released, 0.16.1. This version only bumps its libgit2-sys dependency to ensure no vulnerable libgit2-sys versions are used, but contains no code changes: if you update the libgit2-sys version there is no need to also update the git2 crate version. You can learn more about this vulnerability in libgit2's advisory Fixed in
0.16.1
References
Updated Nov 08, 2023 · Source: OSV.dev |
0.13.12
unknown
Dependencies (11)
+ 3 more |
|
0.13.11
unknown
4 CVEs
RUSTSEC-2026-0184
May 13, 2026
Potential undefined behavior with Signature from a buffer-created BlameHunk When a Fixed in
0.21.0
References Updated Jun 17, 2026 · Source: OSV.dev
RUSTSEC-2026-0183
May 12, 2026
Potential undefined behavior when calling Remote::list() When calling Fixed in
0.21.0
References Updated Jun 17, 2026 · Source: OSV.dev
GHSA-j39j-6gw9-jw6h
RUSTSEC-2026-0008
Feb 04, 2026
git2 has potential undefined behavior when dereferencing Buf struct
Low
Network
Low
None
None
If the Buf struct is dereferenced immediately after calling new() or default() on the Buf struct, a null pointer is passed to the unsafe function slice::from_raw_parts. According to the safety section documentation of the function, data must be non-null and aligned even for zero-length slices or slices of ZSTs. Thus, passing a null pointer will lead to undefined behavior. Fixed in
0.20.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-22742
GHSA-m4ch-rfv5-x5g3
GHSA-8643-3wh5-rmjq
RUSTSEC-2023-0003
Jan 20, 2023
git2-rs fails to verify SSH keys by default
6.8
/ 10
Medium
Network
High
None
Required
Unchanged
High
High
None
The git2 and libgit2-sys crates are Rust wrappers around the libgit2 C library. It was discovered that libgit2 1.5.0 and below did not verify SSH host keys when establishing an SSH connection, exposing users of the library to Man-In-the-Middle attacks. The libgit2 team assigned CVE-2023-22742 to this vulnerability. The following versions of the libgit2-sys Rust crate have been released:
A new git2 crate version has also been released, 0.16.1. This version only bumps its libgit2-sys dependency to ensure no vulnerable libgit2-sys versions are used, but contains no code changes: if you update the libgit2-sys version there is no need to also update the git2 crate version. You can learn more about this vulnerability in libgit2's advisory Fixed in
0.16.1
References
Updated Nov 08, 2023 · Source: OSV.dev |
0.13.11
unknown
Dependencies (11)
+ 3 more |
|
0.13.10
unknown
4 CVEs
RUSTSEC-2026-0184
May 13, 2026
Potential undefined behavior with Signature from a buffer-created BlameHunk When a Fixed in
0.21.0
References Updated Jun 17, 2026 · Source: OSV.dev
RUSTSEC-2026-0183
May 12, 2026
Potential undefined behavior when calling Remote::list() When calling Fixed in
0.21.0
References Updated Jun 17, 2026 · Source: OSV.dev
GHSA-j39j-6gw9-jw6h
RUSTSEC-2026-0008
Feb 04, 2026
git2 has potential undefined behavior when dereferencing Buf struct
Low
Network
Low
None
None
If the Buf struct is dereferenced immediately after calling new() or default() on the Buf struct, a null pointer is passed to the unsafe function slice::from_raw_parts. According to the safety section documentation of the function, data must be non-null and aligned even for zero-length slices or slices of ZSTs. Thus, passing a null pointer will lead to undefined behavior. Fixed in
0.20.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-22742
GHSA-m4ch-rfv5-x5g3
GHSA-8643-3wh5-rmjq
RUSTSEC-2023-0003
Jan 20, 2023
git2-rs fails to verify SSH keys by default
6.8
/ 10
Medium
Network
High
None
Required
Unchanged
High
High
None
The git2 and libgit2-sys crates are Rust wrappers around the libgit2 C library. It was discovered that libgit2 1.5.0 and below did not verify SSH host keys when establishing an SSH connection, exposing users of the library to Man-In-the-Middle attacks. The libgit2 team assigned CVE-2023-22742 to this vulnerability. The following versions of the libgit2-sys Rust crate have been released:
A new git2 crate version has also been released, 0.16.1. This version only bumps its libgit2-sys dependency to ensure no vulnerable libgit2-sys versions are used, but contains no code changes: if you update the libgit2-sys version there is no need to also update the git2 crate version. You can learn more about this vulnerability in libgit2's advisory Fixed in
0.16.1
References
Updated Nov 08, 2023 · Source: OSV.dev |
0.13.10
unknown
Dependencies (11)
+ 3 more |
|
0.13.9
unknown
4 CVEs
RUSTSEC-2026-0184
May 13, 2026
Potential undefined behavior with Signature from a buffer-created BlameHunk When a Fixed in
0.21.0
References Updated Jun 17, 2026 · Source: OSV.dev
RUSTSEC-2026-0183
May 12, 2026
Potential undefined behavior when calling Remote::list() When calling Fixed in
0.21.0
References Updated Jun 17, 2026 · Source: OSV.dev
GHSA-j39j-6gw9-jw6h
RUSTSEC-2026-0008
Feb 04, 2026
git2 has potential undefined behavior when dereferencing Buf struct
Low
Network
Low
None
None
If the Buf struct is dereferenced immediately after calling new() or default() on the Buf struct, a null pointer is passed to the unsafe function slice::from_raw_parts. According to the safety section documentation of the function, data must be non-null and aligned even for zero-length slices or slices of ZSTs. Thus, passing a null pointer will lead to undefined behavior. Fixed in
0.20.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-22742
GHSA-m4ch-rfv5-x5g3
GHSA-8643-3wh5-rmjq
RUSTSEC-2023-0003
Jan 20, 2023
git2-rs fails to verify SSH keys by default
6.8
/ 10
Medium
Network
High
None
Required
Unchanged
High
High
None
The git2 and libgit2-sys crates are Rust wrappers around the libgit2 C library. It was discovered that libgit2 1.5.0 and below did not verify SSH host keys when establishing an SSH connection, exposing users of the library to Man-In-the-Middle attacks. The libgit2 team assigned CVE-2023-22742 to this vulnerability. The following versions of the libgit2-sys Rust crate have been released:
A new git2 crate version has also been released, 0.16.1. This version only bumps its libgit2-sys dependency to ensure no vulnerable libgit2-sys versions are used, but contains no code changes: if you update the libgit2-sys version there is no need to also update the git2 crate version. You can learn more about this vulnerability in libgit2's advisory Fixed in
0.16.1
References
Updated Nov 08, 2023 · Source: OSV.dev |
0.13.9
unknown
Dependencies (11)
+ 3 more |
|
0.13.8
unknown
4 CVEs
RUSTSEC-2026-0184
May 13, 2026
Potential undefined behavior with Signature from a buffer-created BlameHunk When a Fixed in
0.21.0
References Updated Jun 17, 2026 · Source: OSV.dev
RUSTSEC-2026-0183
May 12, 2026
Potential undefined behavior when calling Remote::list() When calling Fixed in
0.21.0
References Updated Jun 17, 2026 · Source: OSV.dev
GHSA-j39j-6gw9-jw6h
RUSTSEC-2026-0008
Feb 04, 2026
git2 has potential undefined behavior when dereferencing Buf struct
Low
Network
Low
None
None
If the Buf struct is dereferenced immediately after calling new() or default() on the Buf struct, a null pointer is passed to the unsafe function slice::from_raw_parts. According to the safety section documentation of the function, data must be non-null and aligned even for zero-length slices or slices of ZSTs. Thus, passing a null pointer will lead to undefined behavior. Fixed in
0.20.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-22742
GHSA-m4ch-rfv5-x5g3
GHSA-8643-3wh5-rmjq
RUSTSEC-2023-0003
Jan 20, 2023
git2-rs fails to verify SSH keys by default
6.8
/ 10
Medium
Network
High
None
Required
Unchanged
High
High
None
The git2 and libgit2-sys crates are Rust wrappers around the libgit2 C library. It was discovered that libgit2 1.5.0 and below did not verify SSH host keys when establishing an SSH connection, exposing users of the library to Man-In-the-Middle attacks. The libgit2 team assigned CVE-2023-22742 to this vulnerability. The following versions of the libgit2-sys Rust crate have been released:
A new git2 crate version has also been released, 0.16.1. This version only bumps its libgit2-sys dependency to ensure no vulnerable libgit2-sys versions are used, but contains no code changes: if you update the libgit2-sys version there is no need to also update the git2 crate version. You can learn more about this vulnerability in libgit2's advisory Fixed in
0.16.1
References
Updated Nov 08, 2023 · Source: OSV.dev |
0.13.8
unknown
Dependencies (11)
+ 3 more |
|
0.13.7
unknown
yanked
4 CVEs
RUSTSEC-2026-0184
May 13, 2026
Potential undefined behavior with Signature from a buffer-created BlameHunk When a Fixed in
0.21.0
References Updated Jun 17, 2026 · Source: OSV.dev
RUSTSEC-2026-0183
May 12, 2026
Potential undefined behavior when calling Remote::list() When calling Fixed in
0.21.0
References Updated Jun 17, 2026 · Source: OSV.dev
GHSA-j39j-6gw9-jw6h
RUSTSEC-2026-0008
Feb 04, 2026
git2 has potential undefined behavior when dereferencing Buf struct
Low
Network
Low
None
None
If the Buf struct is dereferenced immediately after calling new() or default() on the Buf struct, a null pointer is passed to the unsafe function slice::from_raw_parts. According to the safety section documentation of the function, data must be non-null and aligned even for zero-length slices or slices of ZSTs. Thus, passing a null pointer will lead to undefined behavior. Fixed in
0.20.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-22742
GHSA-m4ch-rfv5-x5g3
GHSA-8643-3wh5-rmjq
RUSTSEC-2023-0003
Jan 20, 2023
git2-rs fails to verify SSH keys by default
6.8
/ 10
Medium
Network
High
None
Required
Unchanged
High
High
None
The git2 and libgit2-sys crates are Rust wrappers around the libgit2 C library. It was discovered that libgit2 1.5.0 and below did not verify SSH host keys when establishing an SSH connection, exposing users of the library to Man-In-the-Middle attacks. The libgit2 team assigned CVE-2023-22742 to this vulnerability. The following versions of the libgit2-sys Rust crate have been released:
A new git2 crate version has also been released, 0.16.1. This version only bumps its libgit2-sys dependency to ensure no vulnerable libgit2-sys versions are used, but contains no code changes: if you update the libgit2-sys version there is no need to also update the git2 crate version. You can learn more about this vulnerability in libgit2's advisory Fixed in
0.16.1
References
Updated Nov 08, 2023 · Source: OSV.dev |
0.13.7
unknown
yanked
Dependencies (11)
+ 3 more |
|
0.13.6
unknown
4 CVEs
RUSTSEC-2026-0184
May 13, 2026
Potential undefined behavior with Signature from a buffer-created BlameHunk When a Fixed in
0.21.0
References Updated Jun 17, 2026 · Source: OSV.dev
RUSTSEC-2026-0183
May 12, 2026
Potential undefined behavior when calling Remote::list() When calling Fixed in
0.21.0
References Updated Jun 17, 2026 · Source: OSV.dev
GHSA-j39j-6gw9-jw6h
RUSTSEC-2026-0008
Feb 04, 2026
git2 has potential undefined behavior when dereferencing Buf struct
Low
Network
Low
None
None
If the Buf struct is dereferenced immediately after calling new() or default() on the Buf struct, a null pointer is passed to the unsafe function slice::from_raw_parts. According to the safety section documentation of the function, data must be non-null and aligned even for zero-length slices or slices of ZSTs. Thus, passing a null pointer will lead to undefined behavior. Fixed in
0.20.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-22742
GHSA-m4ch-rfv5-x5g3
GHSA-8643-3wh5-rmjq
RUSTSEC-2023-0003
Jan 20, 2023
git2-rs fails to verify SSH keys by default
6.8
/ 10
Medium
Network
High
None
Required
Unchanged
High
High
None
The git2 and libgit2-sys crates are Rust wrappers around the libgit2 C library. It was discovered that libgit2 1.5.0 and below did not verify SSH host keys when establishing an SSH connection, exposing users of the library to Man-In-the-Middle attacks. The libgit2 team assigned CVE-2023-22742 to this vulnerability. The following versions of the libgit2-sys Rust crate have been released:
A new git2 crate version has also been released, 0.16.1. This version only bumps its libgit2-sys dependency to ensure no vulnerable libgit2-sys versions are used, but contains no code changes: if you update the libgit2-sys version there is no need to also update the git2 crate version. You can learn more about this vulnerability in libgit2's advisory Fixed in
0.16.1
References
Updated Nov 08, 2023 · Source: OSV.dev |
0.13.6
unknown
Dependencies (11)
+ 3 more |
|
0.13.5
unknown
4 CVEs
RUSTSEC-2026-0184
May 13, 2026
Potential undefined behavior with Signature from a buffer-created BlameHunk When a Fixed in
0.21.0
References Updated Jun 17, 2026 · Source: OSV.dev
RUSTSEC-2026-0183
May 12, 2026
Potential undefined behavior when calling Remote::list() When calling Fixed in
0.21.0
References Updated Jun 17, 2026 · Source: OSV.dev
GHSA-j39j-6gw9-jw6h
RUSTSEC-2026-0008
Feb 04, 2026
git2 has potential undefined behavior when dereferencing Buf struct
Low
Network
Low
None
None
If the Buf struct is dereferenced immediately after calling new() or default() on the Buf struct, a null pointer is passed to the unsafe function slice::from_raw_parts. According to the safety section documentation of the function, data must be non-null and aligned even for zero-length slices or slices of ZSTs. Thus, passing a null pointer will lead to undefined behavior. Fixed in
0.20.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-22742
GHSA-m4ch-rfv5-x5g3
GHSA-8643-3wh5-rmjq
RUSTSEC-2023-0003
Jan 20, 2023
git2-rs fails to verify SSH keys by default
6.8
/ 10
Medium
Network
High
None
Required
Unchanged
High
High
None
The git2 and libgit2-sys crates are Rust wrappers around the libgit2 C library. It was discovered that libgit2 1.5.0 and below did not verify SSH host keys when establishing an SSH connection, exposing users of the library to Man-In-the-Middle attacks. The libgit2 team assigned CVE-2023-22742 to this vulnerability. The following versions of the libgit2-sys Rust crate have been released:
A new git2 crate version has also been released, 0.16.1. This version only bumps its libgit2-sys dependency to ensure no vulnerable libgit2-sys versions are used, but contains no code changes: if you update the libgit2-sys version there is no need to also update the git2 crate version. You can learn more about this vulnerability in libgit2's advisory Fixed in
0.16.1
References
Updated Nov 08, 2023 · Source: OSV.dev |
0.13.5
unknown
Dependencies (11)
+ 3 more |
|
0.13.4
unknown
4 CVEs
RUSTSEC-2026-0184
May 13, 2026
Potential undefined behavior with Signature from a buffer-created BlameHunk When a Fixed in
0.21.0
References Updated Jun 17, 2026 · Source: OSV.dev
RUSTSEC-2026-0183
May 12, 2026
Potential undefined behavior when calling Remote::list() When calling Fixed in
0.21.0
References Updated Jun 17, 2026 · Source: OSV.dev
GHSA-j39j-6gw9-jw6h
RUSTSEC-2026-0008
Feb 04, 2026
git2 has potential undefined behavior when dereferencing Buf struct
Low
Network
Low
None
None
If the Buf struct is dereferenced immediately after calling new() or default() on the Buf struct, a null pointer is passed to the unsafe function slice::from_raw_parts. According to the safety section documentation of the function, data must be non-null and aligned even for zero-length slices or slices of ZSTs. Thus, passing a null pointer will lead to undefined behavior. Fixed in
0.20.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-22742
GHSA-m4ch-rfv5-x5g3
GHSA-8643-3wh5-rmjq
RUSTSEC-2023-0003
Jan 20, 2023
git2-rs fails to verify SSH keys by default
6.8
/ 10
Medium
Network
High
None
Required
Unchanged
High
High
None
The git2 and libgit2-sys crates are Rust wrappers around the libgit2 C library. It was discovered that libgit2 1.5.0 and below did not verify SSH host keys when establishing an SSH connection, exposing users of the library to Man-In-the-Middle attacks. The libgit2 team assigned CVE-2023-22742 to this vulnerability. The following versions of the libgit2-sys Rust crate have been released:
A new git2 crate version has also been released, 0.16.1. This version only bumps its libgit2-sys dependency to ensure no vulnerable libgit2-sys versions are used, but contains no code changes: if you update the libgit2-sys version there is no need to also update the git2 crate version. You can learn more about this vulnerability in libgit2's advisory Fixed in
0.16.1
References
Updated Nov 08, 2023 · Source: OSV.dev |
0.13.4
unknown
Dependencies (11)
+ 3 more |
|
0.13.3
unknown
4 CVEs
RUSTSEC-2026-0184
May 13, 2026
Potential undefined behavior with Signature from a buffer-created BlameHunk When a Fixed in
0.21.0
References Updated Jun 17, 2026 · Source: OSV.dev
RUSTSEC-2026-0183
May 12, 2026
Potential undefined behavior when calling Remote::list() When calling Fixed in
0.21.0
References Updated Jun 17, 2026 · Source: OSV.dev
GHSA-j39j-6gw9-jw6h
RUSTSEC-2026-0008
Feb 04, 2026
git2 has potential undefined behavior when dereferencing Buf struct
Low
Network
Low
None
None
If the Buf struct is dereferenced immediately after calling new() or default() on the Buf struct, a null pointer is passed to the unsafe function slice::from_raw_parts. According to the safety section documentation of the function, data must be non-null and aligned even for zero-length slices or slices of ZSTs. Thus, passing a null pointer will lead to undefined behavior. Fixed in
0.20.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-22742
GHSA-m4ch-rfv5-x5g3
GHSA-8643-3wh5-rmjq
RUSTSEC-2023-0003
Jan 20, 2023
git2-rs fails to verify SSH keys by default
6.8
/ 10
Medium
Network
High
None
Required
Unchanged
High
High
None
The git2 and libgit2-sys crates are Rust wrappers around the libgit2 C library. It was discovered that libgit2 1.5.0 and below did not verify SSH host keys when establishing an SSH connection, exposing users of the library to Man-In-the-Middle attacks. The libgit2 team assigned CVE-2023-22742 to this vulnerability. The following versions of the libgit2-sys Rust crate have been released:
A new git2 crate version has also been released, 0.16.1. This version only bumps its libgit2-sys dependency to ensure no vulnerable libgit2-sys versions are used, but contains no code changes: if you update the libgit2-sys version there is no need to also update the git2 crate version. You can learn more about this vulnerability in libgit2's advisory Fixed in
0.16.1
References
Updated Nov 08, 2023 · Source: OSV.dev |
0.13.3
unknown
Dependencies (11)
+ 3 more |
|
0.13.2
unknown
4 CVEs
RUSTSEC-2026-0184
May 13, 2026
Potential undefined behavior with Signature from a buffer-created BlameHunk When a Fixed in
0.21.0
References Updated Jun 17, 2026 · Source: OSV.dev
RUSTSEC-2026-0183
May 12, 2026
Potential undefined behavior when calling Remote::list() When calling Fixed in
0.21.0
References Updated Jun 17, 2026 · Source: OSV.dev
GHSA-j39j-6gw9-jw6h
RUSTSEC-2026-0008
Feb 04, 2026
git2 has potential undefined behavior when dereferencing Buf struct
Low
Network
Low
None
None
If the Buf struct is dereferenced immediately after calling new() or default() on the Buf struct, a null pointer is passed to the unsafe function slice::from_raw_parts. According to the safety section documentation of the function, data must be non-null and aligned even for zero-length slices or slices of ZSTs. Thus, passing a null pointer will lead to undefined behavior. Fixed in
0.20.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-22742
GHSA-m4ch-rfv5-x5g3
GHSA-8643-3wh5-rmjq
RUSTSEC-2023-0003
Jan 20, 2023
git2-rs fails to verify SSH keys by default
6.8
/ 10
Medium
Network
High
None
Required
Unchanged
High
High
None
The git2 and libgit2-sys crates are Rust wrappers around the libgit2 C library. It was discovered that libgit2 1.5.0 and below did not verify SSH host keys when establishing an SSH connection, exposing users of the library to Man-In-the-Middle attacks. The libgit2 team assigned CVE-2023-22742 to this vulnerability. The following versions of the libgit2-sys Rust crate have been released:
A new git2 crate version has also been released, 0.16.1. This version only bumps its libgit2-sys dependency to ensure no vulnerable libgit2-sys versions are used, but contains no code changes: if you update the libgit2-sys version there is no need to also update the git2 crate version. You can learn more about this vulnerability in libgit2's advisory Fixed in
0.16.1
References
Updated Nov 08, 2023 · Source: OSV.dev |
0.13.2
unknown
Dependencies (11)
+ 3 more |
|
0.13.1
unknown
4 CVEs
RUSTSEC-2026-0184
May 13, 2026
Potential undefined behavior with Signature from a buffer-created BlameHunk When a Fixed in
0.21.0
References Updated Jun 17, 2026 · Source: OSV.dev
RUSTSEC-2026-0183
May 12, 2026
Potential undefined behavior when calling Remote::list() When calling Fixed in
0.21.0
References Updated Jun 17, 2026 · Source: OSV.dev
GHSA-j39j-6gw9-jw6h
RUSTSEC-2026-0008
Feb 04, 2026
git2 has potential undefined behavior when dereferencing Buf struct
Low
Network
Low
None
None
If the Buf struct is dereferenced immediately after calling new() or default() on the Buf struct, a null pointer is passed to the unsafe function slice::from_raw_parts. According to the safety section documentation of the function, data must be non-null and aligned even for zero-length slices or slices of ZSTs. Thus, passing a null pointer will lead to undefined behavior. Fixed in
0.20.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-22742
GHSA-m4ch-rfv5-x5g3
GHSA-8643-3wh5-rmjq
RUSTSEC-2023-0003
Jan 20, 2023
git2-rs fails to verify SSH keys by default
6.8
/ 10
Medium
Network
High
None
Required
Unchanged
High
High
None
The git2 and libgit2-sys crates are Rust wrappers around the libgit2 C library. It was discovered that libgit2 1.5.0 and below did not verify SSH host keys when establishing an SSH connection, exposing users of the library to Man-In-the-Middle attacks. The libgit2 team assigned CVE-2023-22742 to this vulnerability. The following versions of the libgit2-sys Rust crate have been released:
A new git2 crate version has also been released, 0.16.1. This version only bumps its libgit2-sys dependency to ensure no vulnerable libgit2-sys versions are used, but contains no code changes: if you update the libgit2-sys version there is no need to also update the git2 crate version. You can learn more about this vulnerability in libgit2's advisory Fixed in
0.16.1
References
Updated Nov 08, 2023 · Source: OSV.dev |
0.13.1
unknown
Dependencies (11)
+ 3 more |
|
0.13.0
unknown
4 CVEs
RUSTSEC-2026-0184
May 13, 2026
Potential undefined behavior with Signature from a buffer-created BlameHunk When a Fixed in
0.21.0
References Updated Jun 17, 2026 · Source: OSV.dev
RUSTSEC-2026-0183
May 12, 2026
Potential undefined behavior when calling Remote::list() When calling Fixed in
0.21.0
References Updated Jun 17, 2026 · Source: OSV.dev
GHSA-j39j-6gw9-jw6h
RUSTSEC-2026-0008
Feb 04, 2026
git2 has potential undefined behavior when dereferencing Buf struct
Low
Network
Low
None
None
If the Buf struct is dereferenced immediately after calling new() or default() on the Buf struct, a null pointer is passed to the unsafe function slice::from_raw_parts. According to the safety section documentation of the function, data must be non-null and aligned even for zero-length slices or slices of ZSTs. Thus, passing a null pointer will lead to undefined behavior. Fixed in
0.20.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-22742
GHSA-m4ch-rfv5-x5g3
GHSA-8643-3wh5-rmjq
RUSTSEC-2023-0003
Jan 20, 2023
git2-rs fails to verify SSH keys by default
6.8
/ 10
Medium
Network
High
None
Required
Unchanged
High
High
None
The git2 and libgit2-sys crates are Rust wrappers around the libgit2 C library. It was discovered that libgit2 1.5.0 and below did not verify SSH host keys when establishing an SSH connection, exposing users of the library to Man-In-the-Middle attacks. The libgit2 team assigned CVE-2023-22742 to this vulnerability. The following versions of the libgit2-sys Rust crate have been released:
A new git2 crate version has also been released, 0.16.1. This version only bumps its libgit2-sys dependency to ensure no vulnerable libgit2-sys versions are used, but contains no code changes: if you update the libgit2-sys version there is no need to also update the git2 crate version. You can learn more about this vulnerability in libgit2's advisory Fixed in
0.16.1
References
Updated Nov 08, 2023 · Source: OSV.dev |
0.13.0
unknown
Dependencies (13)
+ 5 more |
|
0.12.0
unknown
4 CVEs
RUSTSEC-2026-0184
May 13, 2026
Potential undefined behavior with Signature from a buffer-created BlameHunk When a Fixed in
0.21.0
References Updated Jun 17, 2026 · Source: OSV.dev
RUSTSEC-2026-0183
May 12, 2026
Potential undefined behavior when calling Remote::list() When calling Fixed in
0.21.0
References Updated Jun 17, 2026 · Source: OSV.dev
GHSA-j39j-6gw9-jw6h
RUSTSEC-2026-0008
Feb 04, 2026
git2 has potential undefined behavior when dereferencing Buf struct
Low
Network
Low
None
None
If the Buf struct is dereferenced immediately after calling new() or default() on the Buf struct, a null pointer is passed to the unsafe function slice::from_raw_parts. According to the safety section documentation of the function, data must be non-null and aligned even for zero-length slices or slices of ZSTs. Thus, passing a null pointer will lead to undefined behavior. Fixed in
0.20.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-22742
GHSA-m4ch-rfv5-x5g3
GHSA-8643-3wh5-rmjq
RUSTSEC-2023-0003
Jan 20, 2023
git2-rs fails to verify SSH keys by default
6.8
/ 10
Medium
Network
High
None
Required
Unchanged
High
High
None
The git2 and libgit2-sys crates are Rust wrappers around the libgit2 C library. It was discovered that libgit2 1.5.0 and below did not verify SSH host keys when establishing an SSH connection, exposing users of the library to Man-In-the-Middle attacks. The libgit2 team assigned CVE-2023-22742 to this vulnerability. The following versions of the libgit2-sys Rust crate have been released:
A new git2 crate version has also been released, 0.16.1. This version only bumps its libgit2-sys dependency to ensure no vulnerable libgit2-sys versions are used, but contains no code changes: if you update the libgit2-sys version there is no need to also update the git2 crate version. You can learn more about this vulnerability in libgit2's advisory Fixed in
0.16.1
References
Updated Nov 08, 2023 · Source: OSV.dev |
0.12.0
unknown
Dependencies (13)
+ 5 more |
|
0.11.0
unknown
4 CVEs
RUSTSEC-2026-0184
May 13, 2026
Potential undefined behavior with Signature from a buffer-created BlameHunk When a Fixed in
0.21.0
References Updated Jun 17, 2026 · Source: OSV.dev
RUSTSEC-2026-0183
May 12, 2026
Potential undefined behavior when calling Remote::list() When calling Fixed in
0.21.0
References Updated Jun 17, 2026 · Source: OSV.dev
GHSA-j39j-6gw9-jw6h
RUSTSEC-2026-0008
Feb 04, 2026
git2 has potential undefined behavior when dereferencing Buf struct
Low
Network
Low
None
None
If the Buf struct is dereferenced immediately after calling new() or default() on the Buf struct, a null pointer is passed to the unsafe function slice::from_raw_parts. According to the safety section documentation of the function, data must be non-null and aligned even for zero-length slices or slices of ZSTs. Thus, passing a null pointer will lead to undefined behavior. Fixed in
0.20.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-22742
GHSA-m4ch-rfv5-x5g3
GHSA-8643-3wh5-rmjq
RUSTSEC-2023-0003
Jan 20, 2023
git2-rs fails to verify SSH keys by default
6.8
/ 10
Medium
Network
High
None
Required
Unchanged
High
High
None
The git2 and libgit2-sys crates are Rust wrappers around the libgit2 C library. It was discovered that libgit2 1.5.0 and below did not verify SSH host keys when establishing an SSH connection, exposing users of the library to Man-In-the-Middle attacks. The libgit2 team assigned CVE-2023-22742 to this vulnerability. The following versions of the libgit2-sys Rust crate have been released:
A new git2 crate version has also been released, 0.16.1. This version only bumps its libgit2-sys dependency to ensure no vulnerable libgit2-sys versions are used, but contains no code changes: if you update the libgit2-sys version there is no need to also update the git2 crate version. You can learn more about this vulnerability in libgit2's advisory Fixed in
0.16.1
References
Updated Nov 08, 2023 · Source: OSV.dev |
0.11.0
unknown
Dependencies (13)
+ 5 more |