git/list[1] front-page[2] threads[3] people[4] search[5] about
 

RE: Security Vulnerability in Git 2.54.0/OpenSSL 3.5.6 Status

From
PTPerson, Tim <tim.person@personent.com>
Date
Jul 1, 2026, 21:39 UTC
Message-ID
<SN4P221MB0713A20D5451F80499B36C4694F62@SN4P221MB0713.NAMP221.PROD.OUTLOOK.COM>
In-Reply-To
<fe8a3a3f-d762-d2c2-9454-a57ac9a75331@gmx.de>
Johannes,
Thank you for the reply. I wasn't sure who to reach out to for this question. I really appreciate the response and the insight related to your process and timing.
Thank you and have a great rest of your day.
Thanks,
Tim
-----Original Message-----
From: Johannes Schindelin <Johannes.Schindelin@gmx.de> 
Sent: Monday, June 29, 2026 6:57 AM
To: Person, Tim <Tim.Person@personent.com>
Cc: git@vger.kernel.org
Subject: Re: Security Vulnerability in Git 2.54.0/OpenSSL 3.5.6 Status
[You don't often get email from johannes.schindelin@gmx.de. Learn why this is important at https://aka.ms/LearnAboutSenderIdentification ]
[CAUTION: This email originated from outside of the organization. Do not click links or open attachments unless you recognize the sender and know the content is safe.]
Hi Tim,
On Sat, 27 Jun 2026, Person, Tim wrote:
Show 7 quoted lines
> I am writing to determine when Git plans to release an update 
> installer to patch the security vulnerability in Git 2.54.0 because of 
> the included OpenSSL executable. This vulnerability is rated 
> "Critical" in the CVE 
> (https://nam10.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww
> .cve.org%2FCVERecord%3Fid%3DCVE-2026-34182&data=05%7C02%7CTim.Person%4
> 0personentcloud.mail.onmicrosoft.com%7Cd04161ef041e4b2492fe08ded5e65ef7%7Ce2de18dc8323462e8c47561025ebc66c%7C0%7C0%7C639183382582991445%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=0dAHZbln7dV%2BrqdlWcsEGfDvkY5k0L%2Fon0NExDAIGzo%3D&reserved=0). An updated version of the OpenSSL.exe fixing this problem has been available since 06/12/2026. I am just wondering if/when you plan to address this major security issue.
OpenSSL.exe is not part of the critical path of Git for Windows. It is merely included as a curiosity for historical reasons. The critical CVE you mentioned does not affect anything in Git itself. Therefore, I did not even consider making an out-of-band release of Git for Windows merely for that OpenSSL v3.5.7 update.
The next Git for Windows release (v2.55.0, likely due later today, may slip to tomorrow) will include OpenSSL v3.5.7.

Ciao, Johannes

Previous: Johannes Schindelin
Message 5 of 5 in “Security Vulnerability in Git 2.54.0/OpenSSL 3.5.6 Status”
  1. Person, TimJun 27, 2026
  2. Todd ZullingerJun 27, 2026
  3. Person, TimJun 27, 2026
  4. Johannes SchindelinJun 29, 2026
  5. Person, TimJul 1, 2026

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.