{"thread":{"id":"65940","subject":"CVE-2026-55200 libssh2","startedAt":"2026-07-07T08:38:37Z","lastAt":"2026-07-07T16:24:55Z","messageCount":4,"participants":["Berner Martin","Johannes Schindelin","Todd Zullinger"],"isPatch":false,"patchVersion":null,"patchTotal":null},"messages":[{"id":"547313","messageId":"ZR5P278MB19814B2CA717210492C13A73F0F02@ZR5P278MB1981.CHEP278.PROD.OUTLOOK.COM","threadId":"65940","inReplyTo":null,"subject":"CVE-2026-55200 libssh2","fromName":"Berner Martin","fromEmail":"martin.berner@qualitasag.ch","sentAt":"2026-07-07T08:38:34Z","receivedAt":"2026-07-07T08:38:37Z","isPatch":false,"body":"Hello,\nThe libssh2 library appears to be relevant in the Git for Windows build. Git depends on libcurl, and libcurl in turn depends on libssh2.\nHowever, even in the latest build, the version still appears to be 1.11.1, which I understand may be affected by vulnerability CVE-2026-55200.\nIs that correct? If so, when can a patched build be expected?\n\nKind regards,\nMartin Berner\n"},{"id":"547323","messageId":"26531fd0-4a21-c8ef-84a9-25c871cde303@gmx.de","threadId":"65940","inReplyTo":"ZR5P278MB19814B2CA717210492C13A73F0F02@ZR5P278MB1981.CHEP278.PROD.OUTLOOK.COM","subject":"Re: CVE-2026-55200 libssh2","fromName":"Johannes Schindelin","fromEmail":"johannes.schindelin@gmx.de","sentAt":"2026-07-07T11:55:49Z","receivedAt":"2026-07-07T11:55:51Z","isPatch":false,"body":"Hi Martin,\n\nOn Tue, 7 Jul 2026, Berner Martin wrote:\n\n> The libssh2 library appears to be relevant in the Git for Windows build.\n\nFor some definition of \"relevant\" ;-)\n\nIn Git for Windows, `libssh2` is only used by `libcurl`, and the way Git\nuses `libcurl`, there is no code path to using libssh2 functionality.\n\nTherefore, I do not consider this critical enough to rush out a new Git\nfor Windows version with a fix.\n\nBesides...\n\n> Git depends on libcurl, and libcurl in turn depends on libssh2.\n> However, even in the latest build, the version still appears to be\n> 1.11.1, which I understand may be affected by vulnerability\n> CVE-2026-55200.\n>\n> Is that correct? If so, when can a patched build be expected?\n\nThat language \"when can a patched build be expected\" can very, very easily\nbe perceived as quite entitled, and hence have the exact opposite effect\nof what you intended. You might want to be more careful in the future when\nyou plan on not even offering to help while demanding work to be done in\nan Open Source project.\n\nBack to your question why Git for Windows still only includes v1.11.1 of\nlibssh2. The answer is rather trivial: MSYS2 (on which Git for Windows is\nbased through a healthy collaboration) includes only that version:\n\nhttps://packages.msys2.org/base/mingw-w64-libssh2\n\nAnd the reason for _that_ might be rooted in the fact that both the\nrepository as well as the website of libssh2 list that as the very latest\navailable version:\n\n- https://github.com/libssh2/libssh2/releases/latest currently redirects\n  to https://github.com/libssh2/libssh2/releases/tag/libssh2-1.11.1\n\n- https://libssh2.org/ says:\n\n  Download\n  libssh2 1.11.1, released on 2024-10-16. *link to Changelog*\n\nEasy explanation, right?\n\nCiao,\nJohannes\n"},{"id":"547324","messageId":"ZR5P278MB19812C0AE7089DB237227299F0F02@ZR5P278MB1981.CHEP278.PROD.OUTLOOK.COM","threadId":"65940","inReplyTo":"26531fd0-4a21-c8ef-84a9-25c871cde303@gmx.de","subject":"AW: CVE-2026-55200 libssh2","fromName":"Berner Martin","fromEmail":"martin.berner@qualitasag.ch","sentAt":"2026-07-07T13:25:38Z","receivedAt":"2026-07-07T13:25:42Z","isPatch":false,"body":"Hello Johannes,\n\nThank you for clarifying that the use of Git in any way cannot lead to the use of libssh2 and that, therefore, the situation is not as critical as it initially seemed to me.\n\nI apologize for the wording that may have sounded demanding. That was not my intention and was partly due to the translator. My days as a software developer are quite a long time ago, and the languages in which Git is written were not among those I worked with. As a result, my ability to contribute directly to the open-source community is rather limited. However, my employer supports the open-source community in other ways, so we are certainly not just beneficiaries.\n\nThank you also for your explanations regarding MSYS2.\n\nKind regards,\nMartin\n\n-----Ursprüngliche Nachricht-----\nVon: Johannes Schindelin <Johannes.Schindelin@gmx.de> \nGesendet: Dienstag, 7. Juli 2026 13:56\nAn: Berner Martin <martin.berner@qualitasag.ch>\nCc: 'git@vger.kernel.org' <git@vger.kernel.org>\nBetreff: Re: CVE-2026-55200 libssh2\n\nHi Martin,\n\nOn Tue, 7 Jul 2026, Berner Martin wrote:\n\n> The libssh2 library appears to be relevant in the Git for Windows build.\n\nFor some definition of \"relevant\" ;-)\n\nIn Git for Windows, `libssh2` is only used by `libcurl`, and the way Git\nuses `libcurl`, there is no code path to using libssh2 functionality.\n\nTherefore, I do not consider this critical enough to rush out a new Git\nfor Windows version with a fix.\n\nBesides...\n\n> Git depends on libcurl, and libcurl in turn depends on libssh2.\n> However, even in the latest build, the version still appears to be\n> 1.11.1, which I understand may be affected by vulnerability\n> CVE-2026-55200.\n>\n> Is that correct? If so, when can a patched build be expected?\n\nThat language \"when can a patched build be expected\" can very, very easily\nbe perceived as quite entitled, and hence have the exact opposite effect\nof what you intended. You might want to be more careful in the future when\nyou plan on not even offering to help while demanding work to be done in\nan Open Source project.\n\nBack to your question why Git for Windows still only includes v1.11.1 of\nlibssh2. The answer is rather trivial: MSYS2 (on which Git for Windows is\nbased through a healthy collaboration) includes only that version:\n\nhttps://packages.msys2.org/base/mingw-w64-libssh2\n\nAnd the reason for _that_ might be rooted in the fact that both the\nrepository as well as the website of libssh2 list that as the very latest\navailable version:\n\n- https://github.com/libssh2/libssh2/releases/latest currently redirects\n  to https://github.com/libssh2/libssh2/releases/tag/libssh2-1.11.1\n\n- https://libssh2.org/ says:\n\n  Download\n  libssh2 1.11.1, released on 2024-10-16. *link to Changelog*\n\nEasy explanation, right?\n\nCiao,\nJohannes\n"},{"id":"547361","messageId":"20260707162452._tjDEpzZ@teonanacatl.net","threadId":"65940","inReplyTo":"26531fd0-4a21-c8ef-84a9-25c871cde303@gmx.de","subject":"Re: CVE-2026-55200 libssh2","fromName":"Todd Zullinger","fromEmail":"tmz@pobox.com","sentAt":"2026-07-07T16:24:52Z","receivedAt":"2026-07-07T16:24:55Z","isPatch":false,"body":"Hi,\n\nJohannes Schindelin wrote:\n> Back to your question why Git for Windows still only includes v1.11.1 of\n> libssh2. The answer is rather trivial: MSYS2 (on which Git for Windows is\n> based through a healthy collaboration) includes only that version:\n> \n> https://packages.msys2.org/base/mingw-w64-libssh2\n> \n> And the reason for _that_ might be rooted in the fact that both the\n> repository as well as the website of libssh2 list that as the very latest\n> available version:\n> \n> - https://github.com/libssh2/libssh2/releases/latest currently redirects\n>   to https://github.com/libssh2/libssh2/releases/tag/libssh2-1.11.1\n> \n> - https://libssh2.org/ says:\n> \n>   Download\n>   libssh2 1.11.1, released on 2024-10-16. *link to Changelog*\n> \n> Easy explanation, right?\n\nIndeed.  :)\n\nAn upstream issue requesting a release to aid in the\ndistribution of these fixes was filed about 2 months ago\n(after CVE-2026-7598, before CVE-2026-55200 and some\nothers):\n\n    https://github.com/libssh2/libssh2/issues/1925\n\nThat may be worth tracking for anyone curious.\n\n-- \nTodd\n"}]}