Количество 6
Количество 6
CVE-2026-87818
(GitPython 3.1.59 fails to restrict the --no-index option in the high-l ...)
CVE-2026-87818
GitPython 3.1.59 fails to restrict the --no-index option in the high-level diff API, allowing attackers to read arbitrary filesystem paths as repository operands. Attackers can combine --no-index with -I/--ignore-matching-lines to create a content-dependent Boolean oracle, repeatedly querying local files to recover single-line secrets through distinguishable success or error responses.
CVE-2026-87818
GitPython 3.1.59 fails to restrict the --no-index option in the high-level diff API, allowing attackers to read arbitrary filesystem paths as repository operands. Attackers can combine --no-index with -I/--ignore-matching-lines to create a content-dependent Boolean oracle, repeatedly querying local files to recover single-line secrets through distinguishable success or error responses.
CVE-2026-87818
GitPython 3.1.59 fails to restrict the --no-index option in the high-l ...
GHSA-rw58-wc66-99g4
GitPython 3.1.59 fails to restrict the --no-index option in the high-level diff API, allowing attackers to read arbitrary filesystem paths as repository operands. Attackers can combine --no-index with -I/--ignore-matching-lines to create a content-dependent Boolean oracle, repeatedly querying local files to recover single-line secrets through distinguishable success or error responses.
BDU:2026-14473
Уязвимость библиотеки Python для взаимодействия с git-репозиториями GitPython, связанная с внедрением или модификацией аргументов, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-87818 (GitPython 3.1.59 fails to restrict the --no-index option in the high-l ...) | CVSS3: 6.5 | 0% Низкий | 6 дней назад | |
CVE-2026-87818 GitPython 3.1.59 fails to restrict the --no-index option in the high-level diff API, allowing attackers to read arbitrary filesystem paths as repository operands. Attackers can combine --no-index with -I/--ignore-matching-lines to create a content-dependent Boolean oracle, repeatedly querying local files to recover single-line secrets through distinguishable success or error responses. | CVSS3: 6.5 | 0% Низкий | 7 дней назад | |
CVE-2026-87818 GitPython 3.1.59 fails to restrict the --no-index option in the high-level diff API, allowing attackers to read arbitrary filesystem paths as repository operands. Attackers can combine --no-index with -I/--ignore-matching-lines to create a content-dependent Boolean oracle, repeatedly querying local files to recover single-line secrets through distinguishable success or error responses. | CVSS3: 6.5 | 0% Низкий | 7 дней назад | |
CVE-2026-87818 GitPython 3.1.59 fails to restrict the --no-index option in the high-l ... | CVSS3: 6.5 | 0% Низкий | 7 дней назад | |
GHSA-rw58-wc66-99g4 GitPython 3.1.59 fails to restrict the --no-index option in the high-level diff API, allowing attackers to read arbitrary filesystem paths as repository operands. Attackers can combine --no-index with -I/--ignore-matching-lines to create a content-dependent Boolean oracle, repeatedly querying local files to recover single-line secrets through distinguishable success or error responses. | CVSS3: 6.5 | 0% Низкий | 7 дней назад | |
BDU:2026-14473 Уязвимость библиотеки Python для взаимодействия с git-репозиториями GitPython, связанная с внедрением или модификацией аргументов, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации | CVSS3: 6.5 | 0% Низкий | 21 день назад |
Уязвимостей на страницу