Known Vulnerabilities for products from Gitpython Project

Listed below are 9 of the newest known vulnerabilities associated with the vendor "Gitpython Project".

These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.

Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2026-44244 json GitPython is a python library used to interact with Git repositories. Prior to version 3.1.49, GitConfigParser.set_value() pa... Not Provided 2026-05-07 2026-05-11
CVE-2026-44243 json GitPython is a python library used to interact with Git repositories. Prior to version 3.1.48, a vulnerability in GitPython a... Not Provided 2026-05-07 2026-05-07
CVE-2026-42284 json GitPython is a python library used to interact with Git repositories. Prior to version 3.1.47, _clone() validates multi_optio... Not Provided 2026-05-07 2026-05-08
CVE-2026-42215 json GitPython is a python library used to interact with Git repositories. From version 3.1.30 to before version 3.1.47, GitPython... Not Provided 2026-05-07 2026-05-11
CVE-2024-22190 json 7.8 - HIGH 2024-01-11 2024-01-18
CVE-2023-41040 json GitPython is a python library used to interact with Git repositories. In order to resolve some git references, GitPython rea... 6.5 - MEDIUM 2023-08-30 2023-09-29
CVE-2023-40590 json GitPython is a python library used to interact with Git repositories. When resolving a program, Python/Windows look for the ... 7.8 - HIGH 2023-08-28 2023-09-05
CVE-2023-40267 json GitPython before 3.1.32 does not block insecure non-multi options in clone and clone_from. NOTE: this issue exists because of... 9.8 - CRITICAL 2023-08-11 2023-11-07
CVE-2022-24439 json All versions of package gitpython are vulnerable to Remote Code Execution (RCE) due to improper user input validation, which ... 9.8 - CRITICAL 2022-12-06 2024-01-09