Kimi cli: GitPython: Denial of Service via catastrophic backtracking (ReDoS) in Actor.name_email_regex — commit author/committer field parsing (CVE-2026-87819)
Description
GitPython's Actor.name_email_regex regular expression is vulnerable to catastrophic backtracking (ReDoS) when parsing commit author or committer fields containing a long string with an unterminated '<'. This causes quadratic CPU exhaustion, leading to denial of service. The vulnerability affects GitPython versions from 1.11.0 up to but not including 1.50.0. A crafted commit object can cause API calls accessing author or committer metadata to hang for over two minutes. This impacts CI runners, code-hosting backends, and repository scanning tools that process untrusted commits. A fix is available.
CVSS v3.1
Score 7.5high
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in GitPython arises from the regular expression used to parse commit author and committer fields: (.*) <(.*?)>. This pattern includes an unbounded greedy group followed by a literal space and '<', which leads to catastrophic backtracking when the input contains a long string with an unterminated '<' (no matching '>'). The regex engine performs O(n²) backtracking attempts, causing CPU exhaustion proportional to the square of the input length. This occurs in the Actor._from_string() method whenever .author or .committer properties are accessed. The vulnerability can be triggered by a crafted git commit object with a malformed author or committer field, which can be introduced via object-level injection bypassing git's usual sanity checks. Empirical tests show that input sizes of 200,000 bytes can cause over 150 seconds of processing time per invocation. This enables denial of service against any service using GitPython to process commit metadata from untrusted sources.
Potential Impact
The vulnerability causes denial of service by exhausting CPU resources during regex evaluation of commit author or committer fields. This can block GitPython API calls for extended periods (minutes) per invocation, affecting continuous integration systems, code hosting backends, and repository scanning pipelines that process commits from untrusted or third-party sources. There is no impact on confidentiality or integrity, only availability. The vulnerability does not require authentication or user interaction beyond supplying a malicious commit object.
Mitigation Recommendations
A patch is available for GitPython that fixes this vulnerability. Users should upgrade to a fixed version at or beyond 1.50.0. Until patched, avoid processing untrusted git commit objects with GitPython or apply input validation to limit author/committer field lengths and ensure proper formatting. The vendor advisory confirms a fix is available; therefore, upgrading is the recommended mitigation.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- BREW-kimi-cli-CVE-2026-87819
- Osv Schema Version
- 1.7.3
- Ecosystems
- ["Homebrew"]
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6acaad8d2cdf04f656514369
Added to database: 10/10/2026, 21:26:37 UTC
Last enriched: 10/10/2026, 21:31:57 UTC
Last updated: 10/10/2026, 21:31:57 UTC
Views: 6
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.