Inefficient regular expression complexity in GitPython - #VU152986
Published: September 30, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to inefficient regular expression complexity in the _re_actor_epoch regular expression used by parse_actor_and_date when processing malformed author, committer, or tagger lines in commit or tag objects. A remote attacker can supply a crafted commit or tag object to cause a denial of service.
Exploitation requires an application to read the affected actor field from an untrusted repository.