Denial of Service Vulnerabilities in GitPython Affect Fedora Users

Denial of Service Vulnerabilities in GitPython Affect Fedora Users

First seen 10 Sep 2026, 15:20 UTC Linuxsecurity 45.0

Article Content

Browse articles
ThreatCluster

Recent updates for GitPython have addressed multiple denial of service vulnerabilities affecting Fedora systems. Version 3.1.60 fixed CVEs GHSA-g5vv-9gxw-82hx, GHSA-whh4-5q6c-9v3x, and GHSA-239g-whfq-7xj9, while version 3.1.61 deprecated a public class regex on Actor due to potential exploitation risks. The latest version, 3.1.62, released on September 7, 2026, resolves GHSA-hmq2-w58f-27jc and is available for installation via the dnf update program. These vulnerabilities could allow attackers to cause service disruptions, impacting users of GitPython on Fedora systems. System administrators are urged to apply the updates promptly to mitigate risks. The updates are critical for maintaining the security and stability of affected systems.

Key Points: • Multiple denial of service vulnerabilities fixed in GitPython for Fedora. • Version 3.1.62 addresses CVE GHSA-hmq2-w58f-27jc, released on September 7, 2026. • System administrators should update to the latest version to ensure security.

Ask AI about this cluster

Timeline

2026-08-26
GitPython version 3.1.60 released
Version 3.1.60 fixed vulnerabilities GHSA-g5vv-9gxw-82hx, GHSA-whh4-5q6c-9v3x, and GHSA-239g-whfq-7xj9.
Linuxsecurity
2026-08-28
GitPython version 3.1.61 released
Version 3.1.61 deprecated a public class regex on Actor due to potential denial of service risks.
Linuxsecurity
2026-09-07
GitPython version 3.1.62 released
Version 3.1.62 fixed GHSA-hmq2-w58f-27jc and is available for installation.
Linuxsecurity