CVE-2026-86081
n8n Git node clone destination-path regular-expression denial of service
- Severity
- high
- Affected product
- n8n
- Affected versions
- n8n < 1.123.76
- Fixed in
- n8n 1.123.76
- Added to NewScan
- 2026-09-09
- Detected by
- NewScan — free, self-hosted
How NewScan reports it
COMPONENT VERSION RANGE
NewScan fingerprints n8n from its response and reports this CVE when the detected version falls inside the affected range below.
Added 2026-09-09. The vendor advisory fixes the 1.x branch in 1.123.76: the Git node matched an attacker-controlled clone destination against a vulnerable regular expression, allowing resource exhaustion. Version-match only; NewScan never sends a ReDoS payload or concludes from timing. The exact 1.x version comes from versionCli in anonymous GET /rest/settings. The affected 2.x branches fixed in 2.37.7 and 2.38.2 are deliberately absent because n8n 2.x publishes no anonymous version (D152); rows for them would never fire.
References
Scan for this yourself — local, in-band scanning is free.
Get NewScan (FREE) →