gpp_maybe Security update for python-gitpython
SUSE-SLE-Module-Python3-15-SP7-2026-4191


This update for python-GitPython fixes the following issues: - CVE-2026-87817: failure to properly validade the git directory location allows attackers to impersonate the git directory using tracked files and execute arbitrary code by placing pre-commit hooks in the tracked hooks directory (bsc#1279905). - CVE-2026-87818: failure to restrict the `--no-index` option in the high-level diff API allows attackers to read arbitrary filesystem paths as repository operands and create content-dependent Boolean oracles (bsc#1279906). - CVE-2026-87819: quadratic backtracking in the `Actor.name_email_regex` regular expression allows attackers to cause CPU exhaustion and a DoS via a commit with a malformed author field (bsc#1279907).


cloud_download Downloads

Python 3 Module 15.7 s390x
  • Packages
    python-GitPython
    Python Git Library
    3.1.34.1693646983.2a2ae77-150400.9.11.1 lock src
    python311-GitPython
    Python Git Library
    3.1.34.1693646983.2a2ae77-150400.9.11.1 lock rpm
Python 3 Module 15.7 aarch64
  • Packages
    python-GitPython
    Python Git Library
    3.1.34.1693646983.2a2ae77-150400.9.11.1 lock src
    python311-GitPython
    Python Git Library
    3.1.34.1693646983.2a2ae77-150400.9.11.1 lock rpm
Python 3 Module 15.7 ppc64le
  • Packages
    python-GitPython
    Python Git Library
    3.1.34.1693646983.2a2ae77-150400.9.11.1 lock src
    python311-GitPython
    Python Git Library
    3.1.34.1693646983.2a2ae77-150400.9.11.1 lock rpm
Python 3 Module 15.7 x86_64
  • Packages
    python-GitPython
    Python Git Library
    3.1.34.1693646983.2a2ae77-150400.9.11.1 lock src
    python311-GitPython
    Python Git Library
    3.1.34.1693646983.2a2ae77-150400.9.11.1 lock rpm