CVE-2026-87819
Awaiting Analysis Awaiting Analysis - Queue

Regular Expression Denial of Service in GitPython

Vulnerability report for CVE-2026-87819, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-09

Last updated on: 2026-09-18

Assigner: VulnCheck

Description

GitPython before 3.1.60 contains a regular expression denial of service vulnerability in Actor.name_email_regex that processes commit author and committer fields. Attackers can craft a commit object with a malformed author field containing an unterminated angle bracket to cause quadratic backtracking, exhausting CPU resources for over two minutes per commit access.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-09
Last Modified
2026-09-18
Generated
2026-09-29
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-27
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
gitpython_developers gitpython to 3.1.60 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-1333 The product uses a regular expression with an inefficient, possibly exponential worst-case computational complexity that consumes excessive CPU cycles.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-87819 is a Denial of Service vulnerability in GitPython caused by a regular expression denial of service (ReDoS) in the Actor.name_email_regex. Attackers craft a commit with a malformed author field containing an unterminated angle bracket, causing the regex engine to enter quadratic backtracking and exhaust CPU resources for over two minutes per commit access.

Detection Guidance

To detect this vulnerability, check if your system uses GitPython versions prior to 3.1.60. Run: pip show gitpython. If the version is less than 3.1.60, the system is vulnerable. Additionally, monitor for unusual CPU usage spikes during Git operations, especially when processing commits with author fields.

Impact Analysis

This vulnerability can disrupt services relying on GitPython by causing CPU exhaustion for over two minutes per commit access. It affects CI runners, code-hosting backends, and repository-scanning pipelines, potentially leading to service downtime or performance degradation.

Compliance Impact

This vulnerability could impact compliance with GDPR and HIPAA by enabling denial of service attacks that disrupt critical systems. For GDPR, availability is a key principle, and prolonged service disruption may violate Article 32 requirements for resilience. For HIPAA, service outages could affect access to electronic protected health information, potentially violating Security Rule requirements for availability and integrity.

Mitigation Strategies

Upgrade GitPython to version 3.1.60 or later immediately. Use: pip install --upgrade gitpython. If upgrading is not possible, implement input validation to limit author/committer field lengths before regex processing. Avoid using vulnerable GitPython APIs like commit.author or repo.iter_commits() on untrusted repositories.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-87819. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart