CVE-2026-87819: GitPython: Denial of Service via catastrophic backtracking (ReDoS) in Actor.name_email_regex — commit author/committer field parsing
GitPython’s Actor.name_email_regex regular expression (git/util.py, line 863)
is vulnerable to catastrophic backtracking (ReDoS — Regular Expression Denial of
Service). When GitPython parses the author or committer header of a git commit
object that contains a long string with an unterminated < (no matching >), the
Python regex engine enters quadratic backtracking, causing complete single-threaded
CPU exhaustion proportional to the square of the input length.
A single crafted commit object can block any GitPython API call that reads
.author or .committer for over two minutes per invocation, enabling denial
of service against CI runners, code-hosting backends, repository-scanning
pipelines, or any service that processes commits from third-party or untrusted
repositories.
References
- github.com/advisories/GHSA-g5vv-9gxw-82hx
- github.com/gitpython-developers/GitPython/commit/751473a5f3221d6f989291cbebcc404353fd3ba8
- github.com/gitpython-developers/GitPython/pull/2215
- github.com/gitpython-developers/GitPython/releases/tag/3.1.60
- github.com/gitpython-developers/GitPython/security/advisories/GHSA-g5vv-9gxw-82hx
- github.com/pypa/advisory-database/tree/main/vulns/gitpython/PYSEC-2026-3984.yaml
- nvd.nist.gov/vuln/detail/CVE-2026-87819
- www.vulncheck.com/advisories/gitpython-before-3.1.60-denial-of-service-via-redos
Code Behaviors & Features
Detect and mitigate CVE-2026-87819 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →