<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T10:54:22.682553+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-14472</id>
    <title>bdu:2026-14472</title>
    <updated>2026-10-02T10:54:22.705027+00:00</updated>
    <content>bdu:2026-14472</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-14472"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-aider-cve-2026-87819</id>
    <title>BREW-aider-CVE-2026-87819 — GitPython: Denial of Service via catastrophic backtracking (ReDoS) in Actor.name_email_regex — commit author/committer…</title>
    <updated>2026-10-02T10:54:22.705060+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: aider</p>
<p>### Summary</p>
<p>GitPython's `Actor.name_email_regex` regular expression (`git/util.py`, line 863)
is vulnerable to catastrophic backtracking (ReDoS — Regular Expression Denial of
Service). When GitPython parses the `author` or `committer` header of a git commit
object that contains a long string with an unterminated `&lt;` (no matching `&gt;`), the
Python regex engine enters quadratic backtracking, causing complete single-threaded
CPU exhaustion proportional to the square of the input length.</p>
<p>A single crafted commit object can block any GitPython API call that reads
`.author` or `.committer` for **over two minutes per invocation**, enabling denial
of service against CI runners, code-hosting backends, repository-scanning
pipelines, or any service that processes commits from third-party or untrusted
repositories.</p>
<p>---</p>
<p>### Details</p>
<p>**Vulnerable file and line:**</p>
<p>`git/util.py`, line 863:</p>
<p>```python
name_email_regex = re.compile(r"(.*) &lt;(.*?)&gt;")
```</p>
<p>This regex is evaluated inside `Actor._from_string()` (line 909) every time
GitPython resolves a commit's `.author` or `.committer` property.</p>
<p>**Full call chain — from public API to vulnerable sink:**</p>
<p>commit.author # any ordinary GitPython API call
└── git/objects/commit.py:917
Commit._deserialize()
└── git/objects/util.py:341
parse_actor_and_date(author_line)
└── git/util.py:909
Actor._from_string(string)
└── Actor.name_email_regex.search(string) ← VULNERABLE</p>
<p>`author_line` is decoded directly from the raw bytes of the git commit ob…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-aider-cve-2026-87819"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-371994</id>
    <title>EUVD-2026-371994</title>
    <updated>2026-10-02T10:54:22.705168+00:00</updated>
    <content>EUVD-2026-371994</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-371994"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-87819</id>
    <title>fkie_cve-2026-87819</title>
    <updated>2026-10-02T10:54:22.705185+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>GitPython before 3.1.60 contains a regular expression denial of service vulnerability in Actor.name_email_regex that processes commit author and committer fields. Attackers can craft a commit object with a malformed author field containing an unterminated angle bracket to cause quadratic backtracking, exhausting CPU resources for over two minutes per commit access.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-87819"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-g5vv-9gxw-82hx</id>
    <title>GHSA-g5vv-9gxw-82hx — GitPython: Denial of Service via catastrophic backtracking (ReDoS) in Actor.name_email_regex — commit author/committer…</title>
    <updated>2026-10-02T10:54:22.705208+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: GitPython</p>
<p>### Summary</p>
<p>GitPython's `Actor.name_email_regex` regular expression (`git/util.py`, line 863)
is vulnerable to catastrophic backtracking (ReDoS — Regular Expression Denial of
Service). When GitPython parses the `author` or `committer` header of a git commit
object that contains a long string with an unterminated `&lt;` (no matching `&gt;`), the
Python regex engine enters quadratic backtracking, causing complete single-threaded
CPU exhaustion proportional to the square of the input length.</p>
<p>A single crafted commit object can block any GitPython API call that reads
`.author` or `.committer` for **over two minutes per invocation**, enabling denial
of service against CI runners, code-hosting backends, repository-scanning
pipelines, or any service that processes commits from third-party or untrusted
repositories.</p>
<p>---</p>
<p>### Details</p>
<p>**Vulnerable file and line:**</p>
<p>`git/util.py`, line 863:</p>
<p>```python
name_email_regex = re.compile(r"(.*) &lt;(.*?)&gt;")
```</p>
<p>This regex is evaluated inside `Actor._from_string()` (line 909) every time
GitPython resolves a commit's `.author` or `.committer` property.</p>
<p>**Full call chain — from public API to vulnerable sink:**</p>
<p>commit.author # any ordinary GitPython API call
└── git/objects/commit.py:917
Commit._deserialize()
└── git/objects/util.py:341
parse_actor_and_date(author_line)
└── git/util.py:909
Actor._from_string(string)
└── Actor.name_email_regex.search(string) ← VULNERABLE</p>
<p>`author_line` is decoded directly from the raw bytes of the git commit ob…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-g5vv-9gxw-82hx"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-4025</id>
    <title>OESA-2026-4025 — python-GitPython security update</title>
    <updated>2026-10-02T10:54:22.705290+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:24.03-LTS-SP1: python-GitPython</p>
<p>**GitPython*is a python library used to interact with Git repositories.GitPython provides object model read and write access to your git repository. Access repository information conveniently, alter the index directly, handle remotes, or go down to low-level object database access with big-files support.With the new object database abstraction added in 0.3, its even possible to implement your own storage mechanisms, the currently available implementations are &amp;amp;apos;cgit&amp;amp;apos; and pure python, which is the default.Documentation The latest documentation can be found here: As this version of GitPython depends on GitDB, which in turn needs smmap to work, installation is a bit more involved if you do a manual installation, instead of using pip.

Security Fix(es):</p>
<p>GitPython before 3.1.60 fails to properly validate the git directory location, allowing attackers to impersonate the git directory using tracked files like gitdir, commondir, and HEAD. Attackers can execute arbitrary code by placing a malicious pre-commit hook in the tracked hooks directory that executes when a victim calls index.commit() on a cloned or opened repository.(CVE-2026-87817)</p>
<p>GitPython 3.1.59 fails to restrict the --no-index option in the high-level diff API, allowing attackers to read arbitrary filesystem paths as repository operands. Attackers can combine --no-index with -I/--ignore-matching-lines to create a content-dependent Boolean oracle, repeatedly querying local files to recover single-lin…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-4025"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:21874-1</id>
    <title>openSUSE-SU-2026:21874-1 — Security update for python-GitPython</title>
    <updated>2026-10-02T10:54:22.705326+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for python-GitPython</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:21874-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2026-3984</id>
    <title>PYSEC-2026-3984</title>
    <updated>2026-10-02T10:54:22.705348+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: gitpython</p>
<p>GitPython before 3.1.60 contains a regular expression denial of service vulnerability in Actor.name_email_regex that processes commit author and committer fields. Attackers can craft a commit object with a malformed author field containing an unterminated angle bracket to cause quadratic backtracking, exhausting CPU resources for over two minutes per commit access.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2026-3984"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-87819</id>
    <title>UBUNTU-CVE-2026-87819</title>
    <updated>2026-10-02T10:54:22.705366+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: python-git, Ubuntu:Pro:16.04:LTS: python-git, Ubuntu:Pro:18.04:LTS: python-git, Ubuntu:Pro:20.04:LTS: python-git, Ubuntu:Pro:22.04:LTS: python-git, Ubuntu:Pro:24.04:LTS: python-git, Ubuntu:Pro:26.04:LTS: python-git</p>
<p>GitPython before 3.1.60 contains a regular expression denial of service vulnerability in Actor.name_email_regex that processes commit author and committer fields. Attackers can craft a commit object with a malformed author field containing an unterminated angle bracket to cause quadratic backtracking, exhausting CPU resources for over two minutes per commit access.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-87819"/>
  </entry>
</feed>
