Re: CVE-2026-55200 libssh2
- From
Johannes Schindelin <johannes.schindelin@gmx.de>
- Date
- Jul 7, 2026, 11:55 UTC
- Message-ID
- <26531fd0-4a21-c8ef-84a9-25c871cde303@gmx.de>
- In-Reply-To
- <ZR5P278MB19814B2CA717210492C13A73F0F02@ZR5P278MB1981.CHEP278.PROD.OUTLOOK.COM>
Hi Martin,
On Tue, 7 Jul 2026, Berner Martin wrote:
> The libssh2 library appears to be relevant in the Git for Windows build.
For some definition of "relevant" ;-)
In Git for Windows, `libssh2` is only used by `libcurl`, and the way Git uses `libcurl`, there is no code path to using libssh2 functionality.
Therefore, I do not consider this critical enough to rush out a new Git for Windows version with a fix.
Besides...
Show 6 quoted lines
> Git depends on libcurl, and libcurl in turn depends on libssh2. > However, even in the latest build, the version still appears to be > 1.11.1, which I understand may be affected by vulnerability > CVE-2026-55200. > > Is that correct? If so, when can a patched build be expected?
That language "when can a patched build be expected" can very, very easily be perceived as quite entitled, and hence have the exact opposite effect of what you intended. You might want to be more careful in the future when you plan on not even offering to help while demanding work to be done in an Open Source project.
Back to your question why Git for Windows still only includes v1.11.1 of libssh2. The answer is rather trivial: MSYS2 (on which Git for Windows is based through a healthy collaboration) includes only that version:
https://packages.msys2.org/base/mingw-w64-libssh2
And the reason for _that_ might be rooted in the fact that both the repository as well as the website of libssh2 list that as the very latest available version:
- https://github.com/libssh2/libssh2/releases/latest currently redirects to https://github.com/libssh2/libssh2/releases/tag/libssh2-1.11.1
- https://libssh2.org/ says:
Download libssh2 1.11.1, released on 2024-10-16. *link to Changelog*
Easy explanation, right?
Ciao, Johannes