← All CVEs NewScan detects
high

CVE-2026-87819

GitPython Actor author/committer parsing regular-expression denial of service

Severity
high
Affected product
GitPython
Affected versions
GitPython < 3.1.60
Fixed in
GitPython 3.1.60
Added to NewScan
2026-09-09
Detected by
NewScan — free, self-hosted

How NewScan reports it

COMPONENT VERSION RANGE

NewScan fingerprints GitPython from its response and reports this CVE when the detected version falls inside the affected range below.

Added 2026-09-09 from the vendor advisory GHSA-g5vv-9gxw-82hx. GitPython before 3.1.60 applies Actor.name_email_regex to attacker-controlled commit author and committer fields, allowing resource exhaustion. Version-match only: mine_versions reads an exact GitPython pin from an anonymously served requirements.txt; NewScan never sends a ReDoS payload or concludes from timing.

References

Scan for this yourself — local, in-band scanning is free.

Get NewScan (FREE) →