CVE-2026-87819
GitPython before 3.1.60 contains a regular expression denial of service vulnerability in Actor.name_email_regex that processes commit author and committer fields. Attackers can craft a commit object with a malformed author field containing an unterminated angle bracket to cause quadratic backtracking, exhausting CPU resources for over two minutes per commit access.
- Published Sep 9, 2026
- CVSS 8.7 high
- 0.5% chance of exploitation in the next 30 days (EPSS)
- Public exploit code is available
- A fix is available