The http_connect function in transports/http.c in libgit2 before 0.24.6 and 0.25.x before 0.25.1 might allow man-in-the-middle attackers to spoof servers by leveraging clobbering of the error variable.
Conclusion & alert: CVE-2016-10130 is rated Moderate Risk (48.6/100): CVSS Medium severity, with medium exploitation likelihood (EPSS 0.70%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-05-30 | 1.05% | 0.70% | -0.36% |
| 2 | 2025-03-30 | 2.61% | 1.05% | -1.56% |
| 3 | 2025-03-29 | — | 2.61% | — |
Full EPSS history (8 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 5.9 | 3.0 | MEDIUM |
|
2.2 | 3.6 | [email protected] |
| 4.3 | 2.0 | MEDIUM |
|
8.6 | 2.9 | [email protected] |
| vendor | priority | summary | link |
|---|---|---|---|
alpine
|
— | CVE-2016-10130: 4 source package rows (libgit2, libgit2-1.0, libgit2-1.1, libgit2-1.5); 12 state rows across 9 repos (3.10-main, 3.11-main, 3.17-community, 3.18-community, 3.19-community, 3.20-community, 3.21-community, 3.22-community, edge-community); fixed 12, open 0. | https://security.alpinelinux.org/vuln/CVE-2016-10130 |
debian
|
not yet assigned | CVE-2016-10130 not yet assigned priority: Debian including 2 source packages (cargo, libgit2), 7 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 7. | https://security-tracker.debian.org/tracker/CVE-2016-10130 |
suse
|
medium | CVE-2016-10130 severity moderate: SUSE including 27 source package names (libgit2-1_1-1.1.1-1.2, libgit2-1_1-32bit-1.1.1-1.2, …), 33 product×package rows across 18 product lines (SUSE Linux Enterprise Module for Development Tools 15, SUSE Linux Enterprise Module for Development Tools 15 SP1, … (18 product lines)): Fixed 33. | https://www.suse.com/security/cve/CVE-2016-10130/ |
ubuntu
|
medium | CVE-2016-10130 medium priority: Ubuntu including 1 source packages (libgit2), 23 status rows across 23 suites (artful, bionic, cosmic, disco, eoan, focal, groovy, hirsute, impish, jammy, kinetic, lunar, mantic, noble, oracular, plucky, precise, questing, trusty, upstream, xenial, yakkety, zesty): not-affected 16, ignored 3, needed 2, DNE 1, released 1. | https://ubuntu.com/security/CVE-2016-10130 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| libgit2_project | libgit2 | <= 0.24.5 | cpe:2.3:a:libgit2_project:libgit2:*:*:*:*:*:*:*:* |
| libgit2_project | libgit2 | 0.25.0 | cpe:2.3:a:libgit2_project:libgit2:0.25.0:*:*:*:*:*:*:* |
| libgit2_project | libgit2 | 0.25.0 | cpe:2.3:a:libgit2_project:libgit2:0.25.0:rc1:*:*:*:*:*:* |
| libgit2_project | libgit2 | 0.25.0 | cpe:2.3:a:libgit2_project:libgit2:0.25.0:rc2:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| http://lists.opensuse.org/opensuse-updates/2017-02/msg00030.html | Third Party Advisory |
| http://lists.opensuse.org/opensuse-updates/2017-02/msg00036.html | Third Party Advisory |
| http://lists.opensuse.org/opensuse-updates/2017-02/msg00072.html | Third Party Advisory |
| http://www.openwall.com/lists/oss-security/2017/01/10/5 | Mailing List Patch Third Party Advisory |
| http://www.openwall.com/lists/oss-security/2017/01/11/6 | Mailing List Patch Third Party Advisory |
| http://www.securityfocus.com/bid/95359 | |
| https://github.com/libgit2/libgit2/commit/9a64e62f0f20c9cf9b2e1609f037060eb2d8eb22 | Issue Tracking Patch Third Party Advisory |
| https://github.com/libgit2/libgit2/commit/b5c6a1b407b7f8b952bded2789593b68b1876211 | Issue Tracking Patch Third Party Advisory |
| https://libgit2.github.com/security/ | Patch Vendor Advisory |