---
id: CVE-2026-73622
title: >-
  gitpython: GitPython: Information disclosure via environment variable
  expansion in URL handling (CVE-2026-73622)
summary: >-
  A flaw was found in GitPython. This vulnerability allows a remote attacker to
  exfiltrate sensitive information, such as environment variables, by crafting
  malicious URLs. When these URLs are processed during Git operations like fetch
  or pu…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'
cvssSource: vendor
cwe: CWE-914
vendor: Red Hat
product: Red Hat OpenShift AI 2.25
affected:
  - exploit_intelligence
  - ai_inference_server
  - enterprise_linux_ai_rhel_ai 3
  - openshift_ai_rhoai
  - satellite 6
  - satellite_6_19_for_rhel 9
  - ansible_automation_platform 2.5
  - ansible_automation_platform 2.6
  - ansible_automation_platform 2.7
  - openshift_ai 2.25
  - satellite 6.18
  - satellite 6.19
patched:
  - satellite_6_19_for_rhel 9
  - ansible_automation_platform 2.5
  - ansible_automation_platform 2.6
  - ansible_automation_platform 2.7
  - openshift_ai 2.25
  - satellite 6.18
  - satellite 6.19
published: '2026-08-13'
updated: '2026-09-24'
sourceUpdated: '2026-09-24T05:59:29+00:00'
source: CSAF
sourceUrl: 'https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-73622.json'
references:
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-73622.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-73622'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2515269'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-73622'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-73622'
  - url: >-
      https://github.com/gitpython-developers/GitPython/commit/8ac5a30519b6f4af85398b9b9d7064ff4d452da2
  - url: >-
      https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-94p4-4cq8-9g67
  - url: >-
      https://www.vulncheck.com/advisories/gitpython-before-environment-variable-exfiltration-via-remote-add
  - url: 'https://access.redhat.com/errata/RHSA-2026:63385'
  - url: 'https://access.redhat.com/errata/RHSA-2026:71210'
  - url: 'https://access.redhat.com/errata/RHSA-2026:71179'
  - url: 'https://access.redhat.com/errata/RHSA-2026:67279'
  - url: 'https://access.redhat.com/errata/RHSA-2026:65126'
  - url: 'https://access.redhat.com/errata/RHSA-2026:68764'
  - url: 'https://access.redhat.com/errata/RHSA-2026:68771'
  - url: 'https://access.redhat.com/errata/RHSA-2026:68780'
  - url: 'https://access.redhat.com/errata/RHSA-2026:68776'
  - url: >-
      https://github.com/gitpython-developers/GitPython/commit/863417457a0633db7ea5aed4fd01e0b291a41162
  - url: 'https://github.com/gitpython-developers/GitPython'
  - url: 'https://github.com/gitpython-developers/GitPython/releases/tag/3.1.55'
tags:
  - csaf
  - vex
  - red-hat
  - osv
  - pip
epss: 0.00354
epssPercentile: 0.29157
aliases:
  - GHSA-94p4-4cq8-9g67
ecosystem: pip
ingestedAt: '2026-08-14T19:18:45.479Z'
---

## Overview

A flaw was found in GitPython. This vulnerability allows a remote attacker to exfiltrate sensitive information, such as environment variables, by crafting malicious URLs. When these URLs are processed during Git operations like fetch or pull, the environment variables are expanded and transmitted to attacker-controlled hosts, leading to information disclosure.

## Vendor advisories

- **RHSA-2026:63385** · Red Hat · fixed in: Red Hat Satellite 6.19 for RHEL 9 · released 2026-09-03 · [advisory](https://access.redhat.com/errata/RHSA-2026:63385)
- **RHSA-2026:71210** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.5 · released 2026-09-23 · [advisory](https://access.redhat.com/errata/RHSA-2026:71210)
- **RHSA-2026:71179** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.6 · released 2026-09-23 · [advisory](https://access.redhat.com/errata/RHSA-2026:71179)
- **RHSA-2026:67279** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.7 · released 2026-09-14 · [advisory](https://access.redhat.com/errata/RHSA-2026:67279)
- **RHSA-2026:65126** · Red Hat · fixed in: Red Hat OpenShift AI 2.25 · released 2026-09-08 · [advisory](https://access.redhat.com/errata/RHSA-2026:65126)
- **RHSA-2026:68764** · Red Hat · fixed in: Red Hat Satellite 6.18 · released 2026-09-17 · [advisory](https://access.redhat.com/errata/RHSA-2026:68764)
- **RHSA-2026:68771** · Red Hat · fixed in: Red Hat Satellite 6.18 · released 2026-09-17 · [advisory](https://access.redhat.com/errata/RHSA-2026:68771)
- **RHSA-2026:68780** · Red Hat · fixed in: Red Hat Satellite 6.19 · released 2026-09-17 · [advisory](https://access.redhat.com/errata/RHSA-2026:68780)
- **RHSA-2026:68776** · Red Hat · fixed in: Red Hat Satellite 6.19 · released 2026-09-17 · [advisory](https://access.redhat.com/errata/RHSA-2026:68776)
- **Red Hat VEX** · Important · affected: Exploit Intelligence, Red Hat AI Inference Server, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat OpenShift AI (RHOAI), Red Hat Satellite 6 · no fix planned: Red Hat AI Inference Server, Exploit Intelligence, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat OpenShift AI (RHOAI), … · updated 2026-09-24 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-73622.json)

**gitpython: GitPython: Information disclosure via environment variable expansion in URL handling** — rated Important by Red Hat. Released 2026-08-13, updated 2026-09-24.

Affected:

- Exploit Intelligence
- Red Hat AI Inference Server
- Red Hat Enterprise Linux AI (RHEL AI) 3
- Red Hat OpenShift AI (RHOAI)
- Red Hat Satellite 6

Fixed:

- Red Hat Satellite 6.19 for RHEL 9
- Red Hat Ansible Automation Platform 2.5
- Red Hat Ansible Automation Platform 2.6
- Red Hat Ansible Automation Platform 2.7
- Red Hat OpenShift AI 2.25
- Red Hat Satellite 6.18
- Red Hat Satellite 6.19

No fix planned:

- Red Hat AI Inference Server
- Exploit Intelligence
- Red Hat Enterprise Linux AI (RHEL AI) 3
- Red Hat OpenShift AI (RHOAI)
- Red Hat Satellite 6

Not affected:

- Red Hat Satellite 6.19 for RHEL 9
- Red Hat Ansible Automation Platform 2.5
- Red Hat Ansible Automation Platform 2.6
- Red Hat Ansible Automation Platform 2.7
- Red Hat OpenShift AI 2.25
- Migration Toolkit for Applications 8
- Pen Drive Powered by Red Hat Lightspeed
- Red Hat Ansible Automation Platform 2
- Red Hat Hardened Images
- Red Hat OpenShift AI (RHOAI)

## Remediation

Before applying this update, make sure all previously released errata
relevant to your system have been applied.

For detailed instructions how to apply this update, refer to:

https://access.redhat.com/documentation/en-us/red_hat_satellite/6.19/html/updating_red_hat_satellite/index https://access.redhat.com/errata/RHSA-2026:63385
Before applying this update, make sure all previously released errata relevant to your system have been applied.
For details on how to apply this update, refer to:
https://docs.redhat.com/en/documentation/red_hat_ansible_automation_platform/2.5#Upgrading https://access.redhat.com/errata/RHSA-2026:71210
Before applying this update, make sure all previously released errata relevant to your system have been applied.
For details on how to apply this update, refer to:
https://docs.redhat.com/en/documentation/red_hat_ansible_automation_platform/2.6#Upgrade https://access.redhat.com/errata/RHSA-2026:71179

Workarounds / mitigations:

- Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

## Package advisory (CVE-2026-73622)

Affected packages:

- `gitpython < 3.1.55`

Patched in:

- `gitpython 3.1.55`

Source: https://osv.dev/vulnerability/GHSA-94p4-4cq8-9g67
