<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 14:42:57 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-14473</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-14473</link>
      <description>bdu:2026-14473</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-14473</guid>
    </item>
    <item>
      <title>BREW-checkov-CVE-2026-87818 — GitPython: --no-index bypasses diff unsafe-option protections and enables a blind local-file content oracle</title>
      <link>https://cve.radiocsirt.org/vuln/brew-checkov-cve-2026-87818</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: checkov&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;GitPython 3.1.59 blocks a previously available local-file read path through unsafe git diff options such as -O/--orderfile.&lt;/p&gt;
&lt;p&gt;However, the high-level diff API still permits --no-index with the default allow_unsafe_options=False.&lt;/p&gt;
&lt;p&gt;--no-index changes the semantics of the paths arguments: instead of repository-relative pathspecs, Git interprets them as arbitrary filesystem paths.&lt;/p&gt;
&lt;p&gt;When combined with the still-allowed -I/--ignore-matching-lines option, this creates a content-dependent Boolean oracle over a caller-selected local file.&lt;/p&gt;
&lt;p&gt;This was reproduced against the published GitPython 3.1.59 wheel.&lt;/p&gt;
&lt;p&gt;The original unsafe-option path is blocked in 3.1.59, while this alternate path remains reachable without setting allow_unsafe_options=True.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;Confirmed API surface:&lt;/p&gt;
&lt;p&gt;repo.index.diff(
    None,
    no_index=True,
    I=pattern,
    paths=[baseline_path, target_path],
    create_patch=True,
)&lt;/p&gt;
&lt;p&gt;The relevant behavior is:&lt;/p&gt;
&lt;p&gt;1. --no-index makes the two values supplied via paths filesystem operands rather than repository pathspecs.
2. -I/--ignore-matching-lines makes Git&amp;#39;s result depend on whether the supplied regular expression matches the relevant file content.
3. GitPython exposes the resulting bit through distinguishable behavior:
   - matching condition: normal return with an empty DiffIndex
   - non-matching condition: GitCommandError with exit status 1&lt;/p&gt;
&lt;p&gt;An application that forwards attacker-influenced diff options and paths and exposes the success/error disti…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: checkov&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;GitPython 3.1.59 blocks a previously available local-file read path through unsafe git diff options such as -O/--orderfile.&lt;/p&gt;
&lt;p&gt;However, the high-level diff API still permits --no-index with the default allow_unsafe_options=False.&lt;/p&gt;
&lt;p&gt;--no-index changes the semantics of the paths arguments: instead of repository-relative pathspecs, Git interprets them as arbitrary filesystem paths.&lt;/p&gt;
&lt;p&gt;When combined with the still-allowed -I/--ignore-matching-lines option, this creates a content-dependent Boolean oracle over a caller-selected local file.&lt;/p&gt;
&lt;p&gt;This was reproduced against the published GitPython 3.1.59 wheel.&lt;/p&gt;
&lt;p&gt;The original unsafe-option path is blocked in 3.1.59, while this alternate path remains reachable without setting allow_unsafe_options=True.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;Confirmed API surface:&lt;/p&gt;
&lt;p&gt;repo.index.diff(
    None,
    no_index=True,
    I=pattern,
    paths=[baseline_path, target_path],
    create_patch=True,
)&lt;/p&gt;
&lt;p&gt;The relevant behavior is:&lt;/p&gt;
&lt;p&gt;1. --no-index makes the two values supplied via paths filesystem operands rather than repository pathspecs.
2. -I/--ignore-matching-lines makes Git&amp;#39;s result depend on whether the supplied regular expression matches the relevant file content.
3. GitPython exposes the resulting bit through distinguishable behavior:
   - matching condition: normal return with an empty DiffIndex
   - non-matching condition: GitCommandError with exit status 1&lt;/p&gt;
&lt;p&gt;An application that forwards attacker-influenced diff options and paths and exposes the success/error disti…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-checkov-cve-2026-87818</guid>
    </item>
    <item>
      <title>EUVD-2026-365613</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-365613</link>
      <description>EUVD-2026-365613</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-365613</guid>
    </item>
    <item>
      <title>fkie_cve-2026-87818</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-87818</link>
      <description>&lt;p&gt;GitPython 3.1.59 fails to restrict the --no-index option in the high-level diff API, allowing attackers to read arbitrary filesystem paths as repository operands. Attackers can combine --no-index with -I/--ignore-matching-lines to create a content-dependent Boolean oracle, repeatedly querying local files to recover single-line secrets through distinguishable success or error responses.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;GitPython 3.1.59 fails to restrict the --no-index option in the high-level diff API, allowing attackers to read arbitrary filesystem paths as repository operands. Attackers can combine --no-index with -I/--ignore-matching-lines to create a content-dependent Boolean oracle, repeatedly querying local files to recover single-line secrets through distinguishable success or error responses.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-87818</guid>
    </item>
    <item>
      <title>Withdrawn: GHSA-rw58-wc66-99g4 — Duplicate Advisory: GitPython 3.1.59: --no-index bypasses diff unsafe-option protections and enables a blind local-file…</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-rw58-wc66-99g4</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: gitpython&lt;/p&gt;
&lt;p&gt;## Duplicate Advisory&lt;/p&gt;
&lt;p&gt;This advisory has been withdrawn because it is a duplicate of GHSA-whh4-5q6c-9v3x. This link is maintained to preserve external references.&lt;/p&gt;
&lt;p&gt;## Original Description
GitPython 3.1.59 fails to restrict the --no-index option in the high-level diff API, allowing attackers to read arbitrary filesystem paths as repository operands. Attackers can combine --no-index with -I/--ignore-matching-lines to create a content-dependent Boolean oracle, repeatedly querying local files to recover single-line secrets through distinguishable success or error responses.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: gitpython&lt;/p&gt;
&lt;p&gt;## Duplicate Advisory&lt;/p&gt;
&lt;p&gt;This advisory has been withdrawn because it is a duplicate of GHSA-whh4-5q6c-9v3x. This link is maintained to preserve external references.&lt;/p&gt;
&lt;p&gt;## Original Description
GitPython 3.1.59 fails to restrict the --no-index option in the high-level diff API, allowing attackers to read arbitrary filesystem paths as repository operands. Attackers can combine --no-index with -I/--ignore-matching-lines to create a content-dependent Boolean oracle, repeatedly querying local files to recover single-line secrets through distinguishable success or error responses.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-rw58-wc66-99g4</guid>
    </item>
    <item>
      <title>OESA-2026-4025 — python-GitPython security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-4025</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP1: python-GitPython&lt;/p&gt;
&lt;p&gt;**GitPython*is a python library used to interact with Git repositories.GitPython provides object model read and write access to your git repository. Access repository information conveniently, alter the index directly, handle remotes, or go down to low-level object database access with big-files support.With the new object database abstraction added in 0.3, its even possible to implement your own storage mechanisms, the currently available implementations are &amp;amp;amp;apos;cgit&amp;amp;amp;apos; and pure python, which is the default.Documentation The latest documentation can be found here: As this version of GitPython depends on GitDB, which in turn needs smmap to work, installation is a bit more involved if you do a manual installation, instead of using pip.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;GitPython before 3.1.60 fails to properly validate the git directory location, allowing attackers to impersonate the git directory using tracked files like gitdir, commondir, and HEAD. Attackers can execute arbitrary code by placing a malicious pre-commit hook in the tracked hooks directory that executes when a victim calls index.commit() on a cloned or opened repository.(CVE-2026-87817)&lt;/p&gt;
&lt;p&gt;GitPython 3.1.59 fails to restrict the --no-index option in the high-level diff API, allowing attackers to read arbitrary filesystem paths as repository operands. Attackers can combine --no-index with -I/--ignore-matching-lines to create a content-dependent Boolean oracle, repeatedly querying local files to recover single-lin…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP1: python-GitPython&lt;/p&gt;
&lt;p&gt;**GitPython*is a python library used to interact with Git repositories.GitPython provides object model read and write access to your git repository. Access repository information conveniently, alter the index directly, handle remotes, or go down to low-level object database access with big-files support.With the new object database abstraction added in 0.3, its even possible to implement your own storage mechanisms, the currently available implementations are &amp;amp;amp;apos;cgit&amp;amp;amp;apos; and pure python, which is the default.Documentation The latest documentation can be found here: As this version of GitPython depends on GitDB, which in turn needs smmap to work, installation is a bit more involved if you do a manual installation, instead of using pip.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;GitPython before 3.1.60 fails to properly validate the git directory location, allowing attackers to impersonate the git directory using tracked files like gitdir, commondir, and HEAD. Attackers can execute arbitrary code by placing a malicious pre-commit hook in the tracked hooks directory that executes when a victim calls index.commit() on a cloned or opened repository.(CVE-2026-87817)&lt;/p&gt;
&lt;p&gt;GitPython 3.1.59 fails to restrict the --no-index option in the high-level diff API, allowing attackers to read arbitrary filesystem paths as repository operands. Attackers can combine --no-index with -I/--ignore-matching-lines to create a content-dependent Boolean oracle, repeatedly querying local files to recover single-lin…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-4025</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:21874-1 — Security update for python-GitPython</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:21874-1</link>
      <description>&lt;p&gt;Security update for python-GitPython&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for python-GitPython&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:21874-1</guid>
    </item>
    <item>
      <title>Withdrawn: PYSEC-2026-3983</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2026-3983</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: gitpython&lt;/p&gt;
&lt;p&gt;GitPython 3.1.59 fails to restrict the --no-index option in the high-level diff API, allowing attackers to read arbitrary filesystem paths as repository operands. Attackers can combine --no-index with -I/--ignore-matching-lines to create a content-dependent Boolean oracle, repeatedly querying local files to recover single-line secrets through distinguishable success or error responses.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: gitpython&lt;/p&gt;
&lt;p&gt;GitPython 3.1.59 fails to restrict the --no-index option in the high-level diff API, allowing attackers to read arbitrary filesystem paths as repository operands. Attackers can combine --no-index with -I/--ignore-matching-lines to create a content-dependent Boolean oracle, repeatedly querying local files to recover single-line secrets through distinguishable success or error responses.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2026-3983</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-87818</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-87818</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: python-git, Ubuntu:Pro:16.04:LTS: python-git, Ubuntu:Pro:18.04:LTS: python-git, Ubuntu:Pro:20.04:LTS: python-git, Ubuntu:Pro:22.04:LTS: python-git, Ubuntu:Pro:24.04:LTS: python-git, Ubuntu:Pro:26.04:LTS: python-git&lt;/p&gt;
&lt;p&gt;GitPython 3.1.59 fails to restrict the --no-index option in the high-level diff API, allowing attackers to read arbitrary filesystem paths as repository operands. Attackers can combine --no-index with -I/--ignore-matching-lines to create a content-dependent Boolean oracle, repeatedly querying local files to recover single-line secrets through distinguishable success or error responses.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: python-git, Ubuntu:Pro:16.04:LTS: python-git, Ubuntu:Pro:18.04:LTS: python-git, Ubuntu:Pro:20.04:LTS: python-git, Ubuntu:Pro:22.04:LTS: python-git, Ubuntu:Pro:24.04:LTS: python-git, Ubuntu:Pro:26.04:LTS: python-git&lt;/p&gt;
&lt;p&gt;GitPython 3.1.59 fails to restrict the --no-index option in the high-level diff API, allowing attackers to read arbitrary filesystem paths as repository operands. Attackers can combine --no-index with -I/--ignore-matching-lines to create a content-dependent Boolean oracle, repeatedly querying local files to recover single-line secrets through distinguishable success or error responses.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-87818</guid>
    </item>
  </channel>
</rss>
