<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T13:38:03.888781+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-12705</id>
    <title>bdu:2026-12705</title>
    <updated>2026-10-03T13:38:04.783202+00:00</updated>
    <content>bdu:2026-12705</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-12705"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-aider-cve-2026-78676</id>
    <title>BREW-aider-CVE-2026-78676 — GitPython: Dormant multi-line git-config values are corrupted into live injected directives (e.g. core.hooksPath) on an…</title>
    <updated>2026-10-03T13:38:04.783274+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: aider</p>
<p>- **CWE:** CWE-88 (Argument Injection) / CWE-94 (Code Injection) — via a read-then-corrupt-on-rewrite config round trip, not a direct setter argument
- **Affected component:** `git/config.py` — `GitConfigParser._read()` (multi-line value decoding, lines 444-541, esp. `string_decode()` at line 460 and its call sites at 519/541) and `GitConfigParser._write()`/`write_section()` (serialization, lines ~694-712, esp. line 708)
- **Affected version:** GitPython at HEAD (`9729ed3b948f2bde09f1f188c5311e172212b67e`, 2026-08-05, VERSION `3.1.58`)</p>
<p>## Reachability
GitPython added `UNSAFE_CONFIG_CHARS_RE` / `_value_to_string_safe()` / `_assure_config_name_safe()` guards (commits `c417af46`, `1ed1b924`, `a495ccd3`, and PR #2176) to reject a Python string containing a raw `\r`/`\n`/NUL byte, or syntax-bearing characters, when it is passed as an **argument** to `set()`, `set_value()`, `add_value()`, or `add_section()`. This closed the four config-injection GHSAs above.</p>
<p>That guard is applied only on the write-argument surface. It is never consulted for values that entered `GitConfigParser._sections` via `_read()` — i.e. values that came from parsing an on-disk config file. And `_read()` legitimately supports standard, spec-compliant git config syntax for multi-line values: a quoted value that is not closed on the same physical line continues onto the next physical line (git's own backslash-continuation syntax), and `string_decode()` (`.decode('unicode_escape')`) decodes a literal two-charac…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-aider-cve-2026-78676"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-359341</id>
    <title>EUVD-2026-359341</title>
    <updated>2026-10-03T13:38:04.783399+00:00</updated>
    <content>EUVD-2026-359341</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-359341"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-78676</id>
    <title>fkie_cve-2026-78676</title>
    <updated>2026-10-03T13:38:04.783414+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupting dormant quoted values into injected directives like core.hooksPath. Attackers can craft config files with embedded newlines that become live git directives after any unrelated GitPython config write, enabling arbitrary code execution via hook invocation.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-78676"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-284h-m62q-gf8w</id>
    <title>GHSA-284h-m62q-gf8w — GitPython: Dormant multi-line git-config values are corrupted into live injected directives (e.g. core.hooksPath) on an…</title>
    <updated>2026-10-03T13:38:04.783438+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: GitPython</p>
<p>- **CWE:** CWE-88 (Argument Injection) / CWE-94 (Code Injection) — via a read-then-corrupt-on-rewrite config round trip, not a direct setter argument
- **Affected component:** `git/config.py` — `GitConfigParser._read()` (multi-line value decoding, lines 444-541, esp. `string_decode()` at line 460 and its call sites at 519/541) and `GitConfigParser._write()`/`write_section()` (serialization, lines ~694-712, esp. line 708)
- **Affected version:** GitPython at HEAD (`9729ed3b948f2bde09f1f188c5311e172212b67e`, 2026-08-05, VERSION `3.1.58`)</p>
<p>## Reachability
GitPython added `UNSAFE_CONFIG_CHARS_RE` / `_value_to_string_safe()` / `_assure_config_name_safe()` guards (commits `c417af46`, `1ed1b924`, `a495ccd3`, and PR #2176) to reject a Python string containing a raw `\r`/`\n`/NUL byte, or syntax-bearing characters, when it is passed as an **argument** to `set()`, `set_value()`, `add_value()`, or `add_section()`. This closed the four config-injection GHSAs above.</p>
<p>That guard is applied only on the write-argument surface. It is never consulted for values that entered `GitConfigParser._sections` via `_read()` — i.e. values that came from parsing an on-disk config file. And `_read()` legitimately supports standard, spec-compliant git config syntax for multi-line values: a quoted value that is not closed on the same physical line continues onto the next physical line (git's own backslash-continuation syntax), and `string_decode()` (`.decode('unicode_escape')`) decodes a literal two-charac…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-284h-m62q-gf8w"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-3699</id>
    <title>OESA-2026-3699 — python-GitPython security update</title>
    <updated>2026-10-03T13:38:04.783541+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:24.03-LTS-SP1: python-GitPython</p>
<p>GitPython is a python library used to interact with git repositories, high-level like git-porcelain, or low-level like git-plumbing.

Security Fix(es):</p>
<p>GitPython before 3.1.57 contains an incomplete denylist in the unsafe_git_archive_options guard that omits --add-file and --add-virtual-file options. Attackers can supply these options to Repo.archive() to read arbitrary files from the filesystem and include them in the returned archive.(CVE-2026-73619)</p>
<p>GitPython before 3.1.57 fails to guard git option forwarding in IndexFile.checkout() and TagReference.create(), allowing attackers to pass unsafe options via kwargs. Attackers can use --prefix to overwrite arbitrary files with repository content or -F to read arbitrary files returned in-band.(CVE-2026-73620)</p>
<p>GitPython before 3.1.56 contains an argument injection vulnerability in the Commit.count() method, which forwards keyword arguments to &amp;apos;git rev-list&amp;apos; without the check_unsafe_options guard present in the sibling iter_items method. An attacker who can control options passed to Commit.count (e.g., via an application that forwards a user-supplied options dict) can supply output=&amp;lt;path&amp;gt;, causing &amp;apos;git rev-list --output=&amp;lt;path&amp;gt;&amp;apos; to open and truncate the target file to zero bytes before revision parsing. This allows destruction/blanking of an arbitrary file at the process&amp;apos;s privilege level (no content control, 0-byte truncation).(CVE-2026-73621)</p>
<p>GitPython before 3.1.55 fails to disable env…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-3699"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11615-1</id>
    <title>openSUSE-SU-2026:11615-1 — python313-GitPython-3.1.59-3.1 on GA media</title>
    <updated>2026-10-03T13:38:04.783596+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>python313-GitPython-3.1.59-3.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:11615-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2026-3786</id>
    <title>PYSEC-2026-3786</title>
    <updated>2026-10-03T13:38:04.783616+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: gitpython</p>
<p>GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupting dormant quoted values into injected directives like core.hooksPath. Attackers can craft config files with embedded newlines that become live git directives after any unrelated GitPython config write, enabling arbitrary code execution via hook invocation.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2026-3786"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:68764</id>
    <title>RHSA-2026:68764 — Red Hat Security Advisory: Technical preview of the satellite/iop-vmaas-rhel9 container image</title>
    <updated>2026-10-03T13:38:04.783636+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>net/mail: golang: Go net/mail: Denial of Service via crafted email inputs GitPython: GitPython: Arbitrary command execution due to bypass of dangerous Git option checks GitPython: GitPython: Arbitrary code execution via improper validation of clone options net/mail: golang: net/mail: Denial of Service via pathological email address parsing GitPython: GitPython: Arbitrary code execution via injected newlines in Git configuration openssl: openssl-src: OpenSSL: Memory leak leads to Denial of Service in OCSP response checking golang.org/x/text: golang.org/x/text: Denial of Service via invalid UTF-8 input net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue gitpython: GitPython: Arbitrary file overwrite and read via unsafe git option forwarding gitpython: GitPython: Information disclosure via environment variable expansion in URL handling gitpython: GitPython: Remote Code Execution via malicious Git template gitpython: GitPython: Arbitrary File Overwrite via improper git option validation gitpython: GitPython: Remote Code Execution via kwarg value smuggling gitpython: GitPython: Remote Code Execution via malicious Git hooks gitpython: GitPython: Arbitrary File Overwrite via `git read-tree` option injection gitpython: GitPython: Arbitrary command execution via crafted kwargs gitpython: GitPython: Arbitrary code execution via config-name injection gitpython: G…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:68764"/>
  </entry>
</feed>
