Advisories » MGASA-2026-0450

Updated python-gitpython packages fix security vulnerabilities

Publication date: 25 Sep 2026
Modification date: 25 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-87819

Description

Denial of Service via catastrophic backtracking (ReDoS) in
Actor.name_email_regex — commit author/committer field parsing
Repository content can impersonate the git directory, leading to
arbitrary code execution
Residual of GHSA-hmq2-w58f-27jc: the fix validates the `.gitmodules`
**name** but the sibling **path** field still reaches `os.makedirs()`
unguarded, although GitPython already owns the containment guard
                

References

SRPMS

10/core

9/core