GHSA-qpf5-3wfw-fh7qHigh· 7.5▾ TwilightDuplicate Advisory: Denial of Service via catastrophic backtracking (ReDoS) in Actor.name_email_regex — commit author/committer field parsing
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
Last analysed / modified upstream
This advisory has been withdrawn because it is a duplicate of GHSA-g5vv-9gxw-82hx. This link is maintained to preserve external references.
GitPython before 3.1.60 contains a regular expression denial of service vulnerability in Actor.name_email_regex that processes commit author and committer fields. Attackers can craft a commit object with a malformed author field containing an unterminated angle bracket to cause quadratic backtracking, exhausting CPU resources for over two minutes per commit access.
gitpython <= 3.1.59Refer to the advisory for the patched release.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-87819High· 7.5GitPython before 3.1.60 contains a regular expression denial of service vulnerability in Actor.name_email_regex that processes commit author and committer fields
GHSA-59cr-6r3x-644wMediumGitPython submodule update path traversal can write outside the repository
GHSA-2pxq-5vcg-rq29High· 8.8Duplicate Advisory: Repository content can impersonate the git directory, leading to arbitrary code execution
GHSA-whh4-5q6c-9v3xMedium· 6.5GitPython: --no-index bypasses diff unsafe-option protections and enables a blind local-file content oracle
CVE-2023-40590High· 7.8GitPython untrusted search path on Windows systems leading to arbitrary code execution
CVE-2024-22190High· 7.8Untrusted search path under some conditions on Windows allows arbitrary code execution