git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: Security Vulnerability in Git 2.54.0/OpenSSL 3.5.6 Status

From
Todd Zullinger <tmz@pobox.com>
Date
Jun 27, 2026, 21:07 UTC
Message-ID
<20260627210718.zl0eH_Sc@teonanacatl.net>
In-Reply-To
<SN4P221MB0713994458A94BFCB51F7AC494EA2@SN4P221MB0713.NAMP221.PROD.OUTLOOK.COM>
Hi,
Person, Tim wrote:
Show 8 quoted lines
> I am writing to determine when Git plans to release an
> update installer to patch the security vulnerability in
> Git 2.54.0 because of the included OpenSSL executable.
> This vulnerability is rated "Critical" in the CVE
> (https://www.cve.org/CVERecord?id=CVE-2026-34182). An
> updated version of the OpenSSL.exe fixing this problem has
> been available since 06/12/2026. I am just wondering
> if/when you plan to address this major security issue.

The Git project does not distribute any binaries. You likely want to direct this to the Git for Windows project¹.

That said, it's not even clear to me that the CVE you reference affects git's usage of OpenSSL.

From a little skimming, the issue affects use of CMS (which is something like the successor to S/MIME, as far as I can tell).

The only place where git gets close to that area is if you configure it to use x509 as gpg.program. And then git uses gpgsm, which is not affected by the CVE in OpenSSL.

¹ https://gitforwindows.org/
-- 
Todd
Previous: Person, TimNext: Person, Tim
Message 2 of 5 in “Security Vulnerability in Git 2.54.0/OpenSSL 3.5.6 Status”
  1. Person, TimJun 27, 2026
  2. Todd ZullingerJun 27, 2026
  3. Person, TimJun 27, 2026
  4. Johannes SchindelinJun 29, 2026
  5. Person, TimJul 1, 2026

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.