{"thread":{"id":"65880","subject":"Security Vulnerability in Git 2.54.0/OpenSSL 3.5.6 Status","startedAt":"2026-06-27T19:19:42Z","lastAt":"2026-07-01T21:39:47Z","messageCount":5,"participants":["Person, Tim","Todd Zullinger","Johannes Schindelin"],"isPatch":false,"patchVersion":null,"patchTotal":null},"messages":[{"id":"546560","messageId":"SN4P221MB0713994458A94BFCB51F7AC494EA2@SN4P221MB0713.NAMP221.PROD.OUTLOOK.COM","threadId":"65880","inReplyTo":null,"subject":"Security Vulnerability in Git 2.54.0/OpenSSL 3.5.6 Status","fromName":"Person, Tim","fromEmail":"tim.person@personent.com","sentAt":"2026-06-27T19:18:38Z","receivedAt":"2026-06-27T19:19:42Z","isPatch":false,"body":"Good afternoon,\n\nI am writing to determine when Git plans to release an update installer to patch the security vulnerability in Git 2.54.0 because of the included OpenSSL executable. This vulnerability is rated \"Critical\" in the CVE (https://www.cve.org/CVERecord?id=CVE-2026-34182). An updated version of the OpenSSL.exe fixing this problem has been available since 06/12/2026. I am just wondering if/when you plan to address this major security issue.\n\nRespectfully,\n\nTim Person\n\n"},{"id":"546570","messageId":"20260627210718.zl0eH_Sc@teonanacatl.net","threadId":"65880","inReplyTo":"SN4P221MB0713994458A94BFCB51F7AC494EA2@SN4P221MB0713.NAMP221.PROD.OUTLOOK.COM","subject":"Re: Security Vulnerability in Git 2.54.0/OpenSSL 3.5.6 Status","fromName":"Todd Zullinger","fromEmail":"tmz@pobox.com","sentAt":"2026-06-27T21:07:18Z","receivedAt":"2026-06-27T21:07:21Z","isPatch":false,"body":"Hi,\n\nPerson, Tim wrote:\n> I am writing to determine when Git plans to release an\n> update installer to patch the security vulnerability in\n> Git 2.54.0 because of the included OpenSSL executable.\n> This vulnerability is rated \"Critical\" in the CVE\n> (https://www.cve.org/CVERecord?id=CVE-2026-34182). An\n> updated version of the OpenSSL.exe fixing this problem has\n> been available since 06/12/2026. I am just wondering\n> if/when you plan to address this major security issue.\n\nThe Git project does not distribute any binaries.  You\nlikely want to direct this to the Git for Windows project¹.\n\nThat said, it's not even clear to me that the CVE you\nreference affects git's usage of OpenSSL.\n\nFrom a little skimming, the issue affects use of CMS (which\nis something like the successor to S/MIME, as far as I can\ntell).\n\nThe only place where git gets close to that area is if you\nconfigure it to use x509 as gpg.program.  And then git uses\ngpgsm, which is not affected by the CVE in OpenSSL.\n\n¹ https://gitforwindows.org/\n\n-- \nTodd\n"},{"id":"546571","messageId":"SN4P221MB071311FDE610296A5059E8F994EA2@SN4P221MB0713.NAMP221.PROD.OUTLOOK.COM","threadId":"65880","inReplyTo":"20260627210718.zl0eH_Sc@teonanacatl.net","subject":"RE: Security Vulnerability in Git 2.54.0/OpenSSL 3.5.6 Status","fromName":"Person, Tim","fromEmail":"tim.person@personent.com","sentAt":"2026-06-27T21:17:06Z","receivedAt":"2026-06-27T21:17:26Z","isPatch":false,"body":"Todd,\n\nThank you for the reply, the explanation, and the information about who to contact.\n\nThanks,\n\nTim\n\n-----Original Message-----\nFrom: Todd Zullinger <tmz@pobox.com>\nSent: Saturday, June 27, 2026 2:07 PM\nTo: Person, Tim <Tim.Person@personent.com>\nCc: git@vger.kernel.org\nSubject: Re: Security Vulnerability in Git 2.54.0/OpenSSL 3.5.6 Status\n\n[You don't often get email from tmz@pobox.com. Learn why this is important at https://aka.ms/LearnAboutSenderIdentification ]\n\n[CAUTION: This email originated from outside of the organization. Do not click links or open attachments unless you recognize the sender and know the content is safe.]\n\nHi,\n\nPerson, Tim wrote:\n> I am writing to determine when Git plans to release an update\n> installer to patch the security vulnerability in Git 2.54.0 because of\n> the included OpenSSL executable.\n> This vulnerability is rated \"Critical\" in the CVE\n> (https://www/\n> .cve.org%2FCVERecord%3Fid%3DCVE-2026-34182&data=05%7C02%7CTim.Person%4\n> 0personentcloud.mail.onmicrosoft.com%7C350b58458bd84a5312f308ded490243\n> 8%7Ce2de18dc8323462e8c47561025ebc66c%7C0%7C0%7C639181913006654964%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C40000%7C%7C%7C&sdata=caMSGrA%2FfpxkKs2o%2Bg1dE9JuEQQlOK3IBt8BzbZ%2F7GM%3D&reserved=0). An updated version of the OpenSSL.exe fixing this problem has been available since 06/12/2026. I am just wondering if/when you plan to address this major security issue.\n\nThe Git project does not distribute any binaries.  You likely want to direct this to the Git for Windows project¹.\n\nThat said, it's not even clear to me that the CVE you reference affects git's usage of OpenSSL.\n\nFrom a little skimming, the issue affects use of CMS (which is something like the successor to S/MIME, as far as I can tell).\n\nThe only place where git gets close to that area is if you configure it to use x509 as gpg.program.  And then git uses gpgsm, which is not affected by the CVE in OpenSSL.\n\n¹ https://gitforwindows.org/\n\n--\nTodd\n"},{"id":"546669","messageId":"fe8a3a3f-d762-d2c2-9454-a57ac9a75331@gmx.de","threadId":"65880","inReplyTo":"SN4P221MB0713994458A94BFCB51F7AC494EA2@SN4P221MB0713.NAMP221.PROD.OUTLOOK.COM","subject":"Re: Security Vulnerability in Git 2.54.0/OpenSSL 3.5.6 Status","fromName":"Johannes Schindelin","fromEmail":"johannes.schindelin@gmx.de","sentAt":"2026-06-29T13:57:12Z","receivedAt":"2026-06-29T13:57:18Z","isPatch":false,"body":"Hi Tim,\n\nOn Sat, 27 Jun 2026, Person, Tim wrote:\n\n> I am writing to determine when Git plans to release an update installer\n> to patch the security vulnerability in Git 2.54.0 because of the\n> included OpenSSL executable. This vulnerability is rated \"Critical\" in\n> the CVE (https://www.cve.org/CVERecord?id=CVE-2026-34182). An updated\n> version of the OpenSSL.exe fixing this problem has been available since\n> 06/12/2026. I am just wondering if/when you plan to address this major\n> security issue.\n\nOpenSSL.exe is not part of the critical path of Git for Windows. It is\nmerely included as a curiosity for historical reasons. The critical CVE\nyou mentioned does not affect anything in Git itself. Therefore, I did not\neven consider making an out-of-band release of Git for Windows merely for\nthat OpenSSL v3.5.7 update.\n\nThe next Git for Windows release (v2.55.0, likely due later today, may\nslip to tomorrow) will include OpenSSL v3.5.7.\n\nCiao,\nJohannes\n"},{"id":"546944","messageId":"SN4P221MB0713A20D5451F80499B36C4694F62@SN4P221MB0713.NAMP221.PROD.OUTLOOK.COM","threadId":"65880","inReplyTo":"fe8a3a3f-d762-d2c2-9454-a57ac9a75331@gmx.de","subject":"RE: Security Vulnerability in Git 2.54.0/OpenSSL 3.5.6 Status","fromName":"Person, Tim","fromEmail":"tim.person@personent.com","sentAt":"2026-07-01T21:39:30Z","receivedAt":"2026-07-01T21:39:47Z","isPatch":false,"body":"Johannes,\n\nThank you for the reply. I wasn't sure who to reach out to for this question. I really appreciate the response and the insight related to your process and timing.\n\nThank you and have a great rest of your day.\n\nThanks,\n\nTim\n\n-----Original Message-----\nFrom: Johannes Schindelin <Johannes.Schindelin@gmx.de> \nSent: Monday, June 29, 2026 6:57 AM\nTo: Person, Tim <Tim.Person@personent.com>\nCc: git@vger.kernel.org\nSubject: Re: Security Vulnerability in Git 2.54.0/OpenSSL 3.5.6 Status\n\n[You don't often get email from johannes.schindelin@gmx.de. Learn why this is important at https://aka.ms/LearnAboutSenderIdentification ]\n\n[CAUTION: This email originated from outside of the organization. Do not click links or open attachments unless you recognize the sender and know the content is safe.]\n\nHi Tim,\n\nOn Sat, 27 Jun 2026, Person, Tim wrote:\n\n> I am writing to determine when Git plans to release an update \n> installer to patch the security vulnerability in Git 2.54.0 because of \n> the included OpenSSL executable. This vulnerability is rated \n> \"Critical\" in the CVE \n> (https://nam10.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww\n> .cve.org%2FCVERecord%3Fid%3DCVE-2026-34182&data=05%7C02%7CTim.Person%4\n> 0personentcloud.mail.onmicrosoft.com%7Cd04161ef041e4b2492fe08ded5e65ef7%7Ce2de18dc8323462e8c47561025ebc66c%7C0%7C0%7C639183382582991445%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=0dAHZbln7dV%2BrqdlWcsEGfDvkY5k0L%2Fon0NExDAIGzo%3D&reserved=0). An updated version of the OpenSSL.exe fixing this problem has been available since 06/12/2026. I am just wondering if/when you plan to address this major security issue.\n\nOpenSSL.exe is not part of the critical path of Git for Windows. It is merely included as a curiosity for historical reasons. The critical CVE you mentioned does not affect anything in Git itself. Therefore, I did not even consider making an out-of-band release of Git for Windows merely for that OpenSSL v3.5.7 update.\n\nThe next Git for Windows release (v2.55.0, likely due later today, may slip to tomorrow) will include OpenSSL v3.5.7.\n\nCiao,\nJohannes\n"}]}