Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-87819

Опубликовано: 09 сент. 2026
Источник: debian
EPSS Низкий

Описание

GitPython before 3.1.60 contains a regular expression denial of service vulnerability in Actor.name_email_regex that processes commit author and committer fields. Attackers can craft a commit object with a malformed author field containing an unterminated angle bracket to cause quadratic backtracking, exhausting CPU resources for over two minutes per commit access.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
python-gitfixed3.1.61-1package

Примечания

  • https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-g5vv-9gxw-82hx

EPSS

Процентиль: 20%
0.00279
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
8 дней назад

GitPython before 3.1.60 contains a regular expression denial of service vulnerability in Actor.name_email_regex that processes commit author and committer fields. Attackers can craft a commit object with a malformed author field containing an unterminated angle bracket to cause quadratic backtracking, exhausting CPU resources for over two minutes per commit access.

CVSS3: 7.5
nvd
8 дней назад

GitPython before 3.1.60 contains a regular expression denial of service vulnerability in Actor.name_email_regex that processes commit author and committer fields. Attackers can craft a commit object with a malformed author field containing an unterminated angle bracket to cause quadratic backtracking, exhausting CPU resources for over two minutes per commit access.

CVSS3: 7.5
github
8 дней назад

GitPython before 3.1.60 contains a regular expression denial of service vulnerability in Actor.name_email_regex that processes commit author and committer fields. Attackers can craft a commit object with a malformed author field containing an unterminated angle bracket to cause quadratic backtracking, exhausting CPU resources for over two minutes per commit access.

CVSS3: 7.5
fstec
23 дня назад

Уязвимость функции Actor.name_email_regex() библиотеки Python для взаимодействия с git-репозиториями GitPython, позволяющая нарушителю вызвать отказ в обслуживании

suse-cvrf
2 дня назад

Security update for python-GitPython

EPSS

Процентиль: 20%
0.00279
Низкий