High severity7.5NVD Advisory· Published Sep 9, 2026
CVE-2026-87819
CVE-2026-87819
Description
GitPython before 3.1.60 contains a regular expression denial of service vulnerability in Actor.name_email_regex that processes commit author and committer fields. Attackers can craft a commit object with a malformed author field containing an unterminated angle bracket to cause quadratic backtracking, exhausting CPU resources for over two minutes per commit access.
Affected products
2<3.1.60+ 1 more
- (no CPE)range: <3.1.60
- (no CPE)range: <3.1.60
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.