JLSEC-2025-185

    Dashboard / Vulnerabilities / JLSEC-2025-185

    JLSEC-2025-185

    Published: 21 Oct 2025Last Modified: 18 Jul 2026

    Summary: libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a...

    Details: libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality into your application. Using well-crafted inputs to `git_revparse_single` can cause the function to enter an infinite loop, potentially causing a Denial of Service attack in the calling application. The revparse function in `src/libgit2/revparse.c` uses a loop to parse the user-provided spec string. There is an edge-case during parsing that allows a bad actor to force the loop conditions to access arbitrary memory. Potentially, this could also leak memory if the extracted rev spec is reflected back to the attacker. As such, libgit2 versions before 1.4.0 are not affected. Users should upgrade to version 1.6.5 or 1.7.2.

    Affected packages

    Package

    Name: LibGit2_jll

    Purl: pkg:julia/LibGit2_jll?uuid=e37daf67-58a4-590a-8e99-b0245dd2ffc5

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 1.4.3+0
    Fixed -1.7.2+0

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    JLSEC-2025-185 | CVE-DB