{"id":"GHSA-qpf5-3wfw-fh7q","title":"Duplicate Advisory: Denial of Service via catastrophic backtracking (ReDoS) in Actor.name_email_regex — commit author/committer field parsing","summary":"Duplicate Advisory: Denial of Service via catastrophic backtracking (ReDoS) in Actor.name_email_regex — commit author/committer field parsing","severity":"high","cvss":7.5,"cwe":["CWE-1333"],"vendor":"gitpython","product":"gitpython","ecosystem":"pip","affected":["gitpython <= 3.1.59"],"published":"2026-09-09","updated":"2026-09-30","sourceUpdated":"2026-09-30T23:29:04Z","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-qpf5-3wfw-fh7q","references":[{"url":"https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-g5vv-9gxw-82hx"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-87819"},{"url":"https://www.vulncheck.com/advisories/gitpython-before-3.1.60-denial-of-service-via-redos"},{"url":"https://github.com/advisories/GHSA-qpf5-3wfw-fh7q"}],"tags":["ghsa","pip"],"ingestedAt":"2026-09-30T23:29:32.581Z","slug":"GHSA-qpf5-3wfw-fh7q","body":"## Overview\n\n## Duplicate Advisory\n\nThis advisory has been withdrawn because it is a duplicate of GHSA-g5vv-9gxw-82hx. This link is maintained to preserve external references.\n\n## Original Description\nGitPython before 3.1.60 contains a regular expression denial of service vulnerability in Actor.name_email_regex that processes commit author and committer fields. Attackers can craft a commit object with a malformed author field containing an unterminated angle bracket to cause quadratic backtracking, exhausting CPU resources for over two minutes per commit access.\n\n## Affected packages\n\n- `gitpython <= 3.1.59`\n\n## Remediation\n\nRefer to the advisory for the patched release.","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}