Advisory Database
  • Advisories
  • Dependency Scanning
  1. pypi
  2. ›
  3. GitPython
  4. ›
  5. CVE-2026-87819

CVE-2026-87819: GitPython: Denial of Service via catastrophic backtracking (ReDoS) in Actor.name_email_regex — commit author/committer field parsing

September 30, 2026

GitPython’s Actor.name_email_regex regular expression (git/util.py, line 863) is vulnerable to catastrophic backtracking (ReDoS — Regular Expression Denial of Service). When GitPython parses the author or committer header of a git commit object that contains a long string with an unterminated < (no matching >), the Python regex engine enters quadratic backtracking, causing complete single-threaded CPU exhaustion proportional to the square of the input length.

A single crafted commit object can block any GitPython API call that reads .author or .committer for over two minutes per invocation, enabling denial of service against CI runners, code-hosting backends, repository-scanning pipelines, or any service that processes commits from third-party or untrusted repositories.


References

  • github.com/advisories/GHSA-g5vv-9gxw-82hx
  • github.com/gitpython-developers/GitPython/commit/751473a5f3221d6f989291cbebcc404353fd3ba8
  • github.com/gitpython-developers/GitPython/pull/2215
  • github.com/gitpython-developers/GitPython/releases/tag/3.1.60
  • github.com/gitpython-developers/GitPython/security/advisories/GHSA-g5vv-9gxw-82hx
  • github.com/pypa/advisory-database/tree/main/vulns/gitpython/PYSEC-2026-3984.yaml
  • nvd.nist.gov/vuln/detail/CVE-2026-87819
  • www.vulncheck.com/advisories/gitpython-before-3.1.60-denial-of-service-via-redos

Code Behaviors & Features

Detect and mitigate CVE-2026-87819 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 3.1.60

Fixed versions

  • 3.1.60

Solution

Upgrade to version 3.1.60 or above.

Impact 7.5 HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Learn more about CVSS

Weakness

  • CWE-1333: Inefficient Regular Expression Complexity
  • CWE-400: Uncontrolled Resource Consumption

Source file

pypi/GitPython/CVE-2026-87819.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Thu, 01 Oct 2026 00:19:57 +0000.