CVE-2026-40319Disclosure(giskard / giskard)

LOWCVSS 5.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Giskard is an open-source testing framework for AI models. In versions prior to 1.0.2b1, the RegexMatching check passes a user-supplied regular expression pattern directly to Python's re.search() without any timeout or complexity guard. A crafted regex pattern can trigger catastrophic backtracking, causing the process to hang indefinitely. Exploitation requires write access to a check definition and subsequent execution of the test suite. This issue has been fixed in giskard-checks version 1.0.2b1.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-1333

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • giskard

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-04-17); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
giskard

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-04-17: 1Mentions · 2026-04-19: 1Technical Details · 2026-04-17: 1Technical Details · 2026-04-19: 104-1704-19
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-40319 Giskard is an open-source testing framework for AI models. In versions prior to 1.0.2b1, the RegexMatching check passes a user-supplied regular expression pattern dir… https://www.cve.org/CVERecord?id=CVE-2026-40319

    Post summary

    The CVE refers to a flaw in Giskard’s RegexMatching check that allows user‑supplied regex patterns in versions before 1.0.2b1; the text provides the technical nature of the issue but no details of mitigation or exploitation.

    0000084
    57.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-40319 Denial of Service via Catastrophic Backtracking in Giskard AI Testing Framework https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-40319

    Post summary

    The note announces CVE-2026-40319, describing it as a denial‑of‑service flaw caused by catastrophic backtracking in the Giskard AI Testing Framework, but it does not offer PoC, exploits, or mitigation information.

    0000042
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appgiskardgiskard---

Explore more