gpp_maybe
Security update for python-gitpython
SUSE-SLE-Module-Python3-15-SP7-2026-4191
This update for python-GitPython fixes the following issues: - CVE-2026-87817: failure to properly validade the git directory location allows attackers to impersonate the git directory using tracked files and execute arbitrary code by placing pre-commit hooks in the tracked hooks directory (bsc#1279905). - CVE-2026-87818: failure to restrict the `--no-index` option in the high-level diff API allows attackers to read arbitrary filesystem paths as repository operands and create content-dependent Boolean oracles (bsc#1279906). - CVE-2026-87819: quadratic backtracking in the `Actor.name_email_regex` regular expression allows attackers to cause CPU exhaustion and a DoS via a commit with a malformed author field (bsc#1279907).
-
Release DateSep 15 2026
-
References
-
Typesecurity
-
Severityimportant
cloud_download Downloads
Python 3 Module 15.7 s390x
-
Packagespython-GitPython
Python Git Librarypython311-GitPython3.1.34.1693646983.2a2ae77-150400.9.11.1 lock src
Python Git Library3.1.34.1693646983.2a2ae77-150400.9.11.1 lock rpm
Python 3 Module 15.7 aarch64
-
Packagespython-GitPython
Python Git Librarypython311-GitPython3.1.34.1693646983.2a2ae77-150400.9.11.1 lock src
Python Git Library3.1.34.1693646983.2a2ae77-150400.9.11.1 lock rpm
Python 3 Module 15.7 ppc64le
-
Packagespython-GitPython
Python Git Librarypython311-GitPython3.1.34.1693646983.2a2ae77-150400.9.11.1 lock src
Python Git Library3.1.34.1693646983.2a2ae77-150400.9.11.1 lock rpm
Python 3 Module 15.7 x86_64
-
Packagespython-GitPython
Python Git Librarypython311-GitPython3.1.34.1693646983.2a2ae77-150400.9.11.1 lock src
Python Git Library3.1.34.1693646983.2a2ae77-150400.9.11.1 lock rpm