high
CVE-2026-87819
GitPython Actor author/committer parsing regular-expression denial of service
- Severity
- high
- Affected product
- GitPython
- Affected versions
- GitPython < 3.1.60
- Fixed in
- GitPython 3.1.60
- Added to NewScan
- 2026-09-09
- Detected by
- NewScan — free, self-hosted
How NewScan reports it
COMPONENT VERSION RANGE
NewScan fingerprints GitPython from its response and reports this CVE when the detected version falls inside the affected range below.
Added 2026-09-09 from the vendor advisory GHSA-g5vv-9gxw-82hx. GitPython before 3.1.60 applies Actor.name_email_regex to attacker-controlled commit author and committer fields, allowing resource exhaustion. Version-match only: mine_versions reads an exact GitPython pin from an anonymously served requirements.txt; NewScan never sends a ReDoS payload or concludes from timing.
References
Scan for this yourself — local, in-band scanning is free.
Get NewScan (FREE) →