{"id":"openSUSE-SU-2026:21874-1","summary":"Security update for python-GitPython","details":"This update for python-GitPython fixes the following issues:\n\n- CVE-2026-67322: environment-variable exfiltration in `Repo.clone_from()` URL via os.path.expandvars() (bsc#1273357).\n- CVE-2026-67323: unguarded Git options passed as keyword arguments in `Repo.archive()` and `git.ls_remote()` allow\n  for command injection (bsc#1273358).\n- CVE-2026-67325: incomplete command injection blocklist fails to account for git's long-option prefix abbreviation\n  feature and allows for bypass (bsc#1273359).\n- CVE-2026-67326: failure to validate newline characters in the section parameter of `config_writer()` can lead to\n  RCE via `core.hooksPath` (bsc#1273364).\n- CVE-2026-69097: failure to properly escape section names in Git `config` files allows for injection of arbitrary\n  configuration directives through malicious submodule names and can lead to RCE (bsc#1273414).\n- CVE-2026-73619: incomplete denylist in the `unsafe_git_archive_options` guard that omits `--add-file` and `--add-\n  virtual-file` options can lead to arbitrary file reads (bsc#1275755).\n- CVE-2026-73620: failure to guard Git option forwarding in `IndexFile.checkout()` and `TagReference.create()` can lead\n  to arbitrary file reads and writes (bsc#1275756).\n- CVE-2026-73621: argument injection in the `Commit.count()` method allows for destruction/blanking of arbitrary files\n  (bsc#1275757).\n- CVE-2026-73622: failure to disable environment variable expansion in `Remote.create()` and `Submodule.add()` URL\n  handling allows for secret exfiltration via URLs containing variable references (bsc#1275751).\n- CVE-2026-73623: incomplete denylist in `unsafe_git_clone_options` that omits `--template` allows for arbitrary command\n  execution (bsc#1275752).\n- CVE-2026-73624: `Diffable.diff` method fails to validate git options passed through `kwargs`, which can lead to\n  arbitrary file writes (bsc#1275753).\n- CVE-2026-73625: `check_unsafe_options` guard bypass via smuggling of git options inside single-character `kwarg`\n  values can lead to arbitrary code execution (bsc#1275754).\n- CVE-2026-76217: failure to validate options passed to `git rm` and `git checkout` commands in `IndexFile.remove()`\n  and `Head.checkout()` can lead to arbitrary file reads (bsc#1275745).\n- CVE-2026-76218: unguarded git option forwarding in `Repo.init` allows for arbitrary command execution (bsc#1275746).\n- CVE-2026-76219: unguarded `git read-tree` option forwarding in `IndexFile.from_tree/reset/merge_tree` can lead to\n  arbitrary file overwrites (bsc#1275747).\n- CVE-2026-76220: `check_unsafe_options` guard can be bypassed by combining a single-character `kwarg` with\n  `split_single_char_options=False`, which can lead to arbitrary OS command injection (bsc#1275748).\n- CVE-2026-76221: `config-name` injection in the `option-name` validator can lead to remote code execution\n  (bsc#1275749).\n- CVE-2026-76222: failure to validate submodule names from `.gitmodules` files allows creation of Git repositories at\n  arbitrary filesystem paths outside the intended clone directory (bsc#1275750).\n- CVE-2026-78675: failure to disable `merge_includes` when parsing `.gitmodules` can lead to discloseure of local file\n  contents when arbitrary file paths are included via `[include]` directives (bsc#1276434).\n- CVE-2026-78676: failure to safely re-serialize multi-line `git-config` values during write operations can corrupt\n  dormant quoted values into live injected directives (bsc#1276433).\n- CVE-2026-78677: omission of `--separate-git-dir` from `unsafe_git_clone_options` allows for creation of arbitrary git\n  directories outside the intended clone destination (bsc#1276432).\n- CVE-2026-78678: incomplete denylist in the `unsafe_git_revision_options` guard that omits `--contents` and `-S`\n  options allows for reading of arbitrary files when these options to are passed to `Repo.blame()` (bsc#1276431).\n- CVE-2026-78679: positional reference parameter can bypass an unsafe option guard and allows for arbitrary file read\n  via `TagReference.create()` (bsc#1276430).\n- CVE-2026-87817: failure to properly validade the git directory location allows attackers to impersonate the git\n  directory using tracked files and execute arbitrary code by placing pre-commit hooks in the tracked hooks directory\n  (bsc#1279905).\n- CVE-2026-87818: failure to restrict the `--no-index` option in the high-level diff API allows attackers to read\n  arbitrary filesystem paths as repository operands and create content-dependent Boolean oracles (bsc#1279906).\n- CVE-2026-87819: quadratic backtracking in the `Actor.name_email_regex` regular expression allows attackers to cause\n  CPU exhaustion and a DoS via a commit with a malformed author field (bsc#1279907).\n- GitPython unsafe clone option gate bypass through joined short options (bsc#1273498).\n","modified":"2026-09-25T18:23:46.862546547Z","published":"2026-09-18T06:05:46Z","related":["CVE-2026-67322","CVE-2026-67323","CVE-2026-67325","CVE-2026-67326","CVE-2026-69097","CVE-2026-73619","CVE-2026-73620","CVE-2026-73621","CVE-2026-73622","CVE-2026-73623","CVE-2026-73624","CVE-2026-73625","CVE-2026-76217","CVE-2026-76218","CVE-2026-76219","CVE-2026-76220","CVE-2026-76221","CVE-2026-76222","CVE-2026-78675","CVE-2026-78676","CVE-2026-78677","CVE-2026-78678","CVE-2026-78679","CVE-2026-87817","CVE-2026-87818","CVE-2026-87819"],"upstream":["CVE-2026-67322","CVE-2026-67323","CVE-2026-67325","CVE-2026-67326","CVE-2026-69097","CVE-2026-73619","CVE-2026-73620","CVE-2026-73621","CVE-2026-73622","CVE-2026-73623","CVE-2026-73624","CVE-2026-73625","CVE-2026-76217","CVE-2026-76218","CVE-2026-76219","CVE-2026-76220","CVE-2026-76221","CVE-2026-76222","CVE-2026-78675","CVE-2026-78676","CVE-2026-78677","CVE-2026-78678","CVE-2026-78679","CVE-2026-87817","CVE-2026-87818","CVE-2026-87819"],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1273357"},{"type":"REPORT","url":"https://bugzilla.suse.com/1273358"},{"type":"REPORT","url":"https://bugzilla.suse.com/1273359"},{"type":"REPORT","url":"https://bugzilla.suse.com/1273364"},{"type":"REPORT","url":"https://bugzilla.suse.com/1273414"},{"type":"REPORT","url":"https://bugzilla.suse.com/1273498"},{"type":"REPORT","url":"https://bugzilla.suse.com/1275745"},{"type":"REPORT","url":"https://bugzilla.suse.com/1275746"},{"type":"REPORT","url":"https://bugzilla.suse.com/1275747"},{"type":"REPORT","url":"https://bugzilla.suse.com/1275748"},{"type":"REPORT","url":"https://bugzilla.suse.com/1275749"},{"type":"REPORT","url":"https://bugzilla.suse.com/1275750"},{"type":"REPORT","url":"https://bugzilla.suse.com/1275751"},{"type":"REPORT","url":"https://bugzilla.suse.com/1275752"},{"type":"REPORT","url":"https://bugzilla.suse.com/1275753"},{"type":"REPORT","url":"https://bugzilla.suse.com/1275754"},{"type":"REPORT","url":"https://bugzilla.suse.com/1275755"},{"type":"REPORT","url":"https://bugzilla.suse.com/1275756"},{"type":"REPORT","url":"https://bugzilla.suse.com/1275757"},{"type":"REPORT","url":"https://bugzilla.suse.com/1276430"},{"type":"REPORT","url":"https://bugzilla.suse.com/1276431"},{"type":"REPORT","url":"https://bugzilla.suse.com/1276432"},{"type":"REPORT","url":"https://bugzilla.suse.com/1276433"},{"type":"REPORT","url":"https://bugzilla.suse.com/1276434"},{"type":"REPORT","url":"https://bugzilla.suse.com/1279905"},{"type":"REPORT","url":"https://bugzilla.suse.com/1279906"},{"type":"REPORT","url":"https://bugzilla.suse.com/1279907"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-67322"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-67323"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-67325"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-67326"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-69097"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-73619"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-73620"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-73621"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-73622"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-73623"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-73624"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-73625"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-76217"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-76218"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-76219"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-76220"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-76221"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-76222"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-78675"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-78676"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-78677"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-78678"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-78679"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-87817"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-87818"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-87819"}],"affected":[{"package":{"name":"python-GitPython","ecosystem":"openSUSE:Leap 16.0","purl":"pkg:rpm/opensuse/python-GitPython&distro=openSUSE%20Leap%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.1.44-160000.4.1"}]}],"ecosystem_specific":{"binaries":[{"python313-GitPython":"3.1.44-160000.4.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21874-1.json"}}],"schema_version":"1.9.0"}