openSUSE-SU-2026:21874-1

See a problem?
Import Source
https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21874-1.json
JSON Data
https://api.test.osv.dev/v1/vulns/openSUSE-SU-2026:21874-1
Upstream
CVE (26)
Related
Published
2026-09-18T06:05:46Z
Modified
2026-09-25T18:23:46Z
Summary
Security update for python-GitPython
Details

This update for python-GitPython fixes the following issues:

  • CVE-2026-67322: environment-variable exfiltration in Repo.clone_from() URL via os.path.expandvars() (bsc#1273357).
  • CVE-2026-67323: unguarded Git options passed as keyword arguments in Repo.archive() and git.ls_remote() allow for command injection (bsc#1273358).
  • CVE-2026-67325: incomplete command injection blocklist fails to account for git's long-option prefix abbreviation feature and allows for bypass (bsc#1273359).
  • CVE-2026-67326: failure to validate newline characters in the section parameter of config_writer() can lead to RCE via core.hooksPath (bsc#1273364).
  • CVE-2026-69097: failure to properly escape section names in Git config files allows for injection of arbitrary configuration directives through malicious submodule names and can lead to RCE (bsc#1273414).
  • CVE-2026-73619: incomplete denylist in the unsafe_git_archive_options guard that omits --add-file and --add- virtual-file options can lead to arbitrary file reads (bsc#1275755).
  • CVE-2026-73620: failure to guard Git option forwarding in IndexFile.checkout() and TagReference.create() can lead to arbitrary file reads and writes (bsc#1275756).
  • CVE-2026-73621: argument injection in the Commit.count() method allows for destruction/blanking of arbitrary files (bsc#1275757).
  • CVE-2026-73622: failure to disable environment variable expansion in Remote.create() and Submodule.add() URL handling allows for secret exfiltration via URLs containing variable references (bsc#1275751).
  • CVE-2026-73623: incomplete denylist in unsafe_git_clone_options that omits --template allows for arbitrary command execution (bsc#1275752).
  • CVE-2026-73624: Diffable.diff method fails to validate git options passed through kwargs, which can lead to arbitrary file writes (bsc#1275753).
  • CVE-2026-73625: check_unsafe_options guard bypass via smuggling of git options inside single-character kwarg values can lead to arbitrary code execution (bsc#1275754).
  • CVE-2026-76217: failure to validate options passed to git rm and git checkout commands in IndexFile.remove() and Head.checkout() can lead to arbitrary file reads (bsc#1275745).
  • CVE-2026-76218: unguarded git option forwarding in Repo.init allows for arbitrary command execution (bsc#1275746).
  • CVE-2026-76219: unguarded git read-tree option forwarding in IndexFile.from_tree/reset/merge_tree can lead to arbitrary file overwrites (bsc#1275747).
  • CVE-2026-76220: check_unsafe_options guard can be bypassed by combining a single-character kwarg with split_single_char_options=False, which can lead to arbitrary OS command injection (bsc#1275748).
  • CVE-2026-76221: config-name injection in the option-name validator can lead to remote code execution (bsc#1275749).
  • CVE-2026-76222: failure to validate submodule names from .gitmodules files allows creation of Git repositories at arbitrary filesystem paths outside the intended clone directory (bsc#1275750).
  • CVE-2026-78675: failure to disable merge_includes when parsing .gitmodules can lead to discloseure of local file contents when arbitrary file paths are included via [include] directives (bsc#1276434).
  • CVE-2026-78676: failure to safely re-serialize multi-line git-config values during write operations can corrupt dormant quoted values into live injected directives (bsc#1276433).
  • CVE-2026-78677: omission of --separate-git-dir from unsafe_git_clone_options allows for creation of arbitrary git directories outside the intended clone destination (bsc#1276432).
  • CVE-2026-78678: incomplete denylist in the unsafe_git_revision_options guard that omits --contents and -S options allows for reading of arbitrary files when these options to are passed to Repo.blame() (bsc#1276431).
  • CVE-2026-78679: positional reference parameter can bypass an unsafe option guard and allows for arbitrary file read via TagReference.create() (bsc#1276430).
  • CVE-2026-87817: failure to properly validade the git directory location allows attackers to impersonate the git directory using tracked files and execute arbitrary code by placing pre-commit hooks in the tracked hooks directory (bsc#1279905).
  • CVE-2026-87818: failure to restrict the --no-index option in the high-level diff API allows attackers to read arbitrary filesystem paths as repository operands and create content-dependent Boolean oracles (bsc#1279906).
  • CVE-2026-87819: quadratic backtracking in the Actor.name_email_regex regular expression allows attackers to cause CPU exhaustion and a DoS via a commit with a malformed author field (bsc#1279907).
  • GitPython unsafe clone option gate bypass through joined short options (bsc#1273498).
References

Affected packages

openSUSE:Leap 16.0 / python-GitPython

Package

Name
python-GitPython
Purl
pkg:rpm/opensuse/python-GitPython&distro=openSUSE%20Leap%2016.0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.1.44-160000.4.1

Ecosystem specific

{
    "binaries": [
        {
            "python313-GitPython": "3.1.44-160000.4.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21874-1.json"