gpp_maybe
Security update for python-gitpython
SUSE-SLES-16.0-775
This update for python-GitPython fixes the following issues - CVE-2026-42215: command injection via Git options bypass (bsc#1264604). - CVE-2026-42284: unsafe option check validates multi_options before shlex.split transforms it (bsc#1264605). - CVE-2026-44243: path traversal in GitPython reference APIs allows arbitrary file write and delete outside the repository (bsc#1264606). - CVE-2026-44244: newline injection in config_writer().set_value() enables RCE via core.hooksPath (bsc#1264608).
-
Release DateMay 18 2026
-
ReferencesBugzilla: 1264604, 1264605, 1264606, 1264608
CVEs: CVE-2026-42215, CVE-2026-42284, CVE-2026-44243, CVE-2026-44244 -
Typesecurity
-
Severityimportant
cloud_download Downloads
To download packages, you need to log in and have a valid subscription.
SUSE Linux Enterprise Server 16.0 aarch64
-
Packages
SUSE Linux Enterprise Server 16.0 ppc64le
-
Packages
SUSE Linux Enterprise Server 16.0 s390x
-
Packages
SUSE Linux Enterprise Server 16.0 x86_64
-
Packages
SUSE Linux Enterprise Server for SAP applications 16.0 ppc64le
-
Packages
SUSE Linux Enterprise Server for SAP applications 16.0 x86_64
-
Packages