giskard
Evals, red teaming, and test generation for agentic systems
Activity
- Latest release
- 2w ago
- Total releases
- 116
- Cadence
- ~7 days
- Last 12 months
- 6
Details
- License
- unknown
- First release
- Apr 11, 2022
| Version | Released | |
|---|---|---|
3.0.0
major
|
3.0.0
major
Dependencies (4)
|
|
3.0.0rc1
pre
|
3.0.0rc1
pre
Dependencies (4)
|
|
3.0.0b3
pre
|
3.0.0b3
pre
Dependencies (4)
|
|
2.19.2
patch
|
2.19.2
patch
Dependencies (38)
+ 30 more |
|
2.19.1
patch
|
2.19.1
patch
Dependencies (38)
+ 30 more |
|
2.19.0
minor
|
2.19.0
minor
Dependencies (39)
+ 31 more |
|
2.18.0
minor
|
2.18.0
minor
Dependencies (39)
+ 31 more |
|
2.17.0
minor
|
2.17.0
minor
Dependencies (38)
+ 30 more |
|
2.16.2
patch
|
2.16.2
patch
Dependencies (37)
+ 29 more |
|
2.16.1
patch
|
2.16.1
patch
Dependencies (37)
+ 29 more |
|
2.16.0
minor
|
2.16.0
minor
Dependencies (37)
+ 29 more |
|
2.15.5
patch
|
2.15.5
patch
Dependencies (36)
+ 28 more |
|
2.15.4
patch
1 CVE
CVE-2024-52524
PYSEC-2026-1403
GHSA-pjwm-cr36-mwv3
Jul 07, 2026
ReDoS in giskard's transformation.py (GHSL-2024-324)
Medium
Network
Low
None
None
ReDoS in Giskard text perturbation detectorA Remote Code Execution (ReDoS) vulnerability was discovered in Giskard component by the GitHub Security Lab team. When processing datasets with specific text patterns with Giskard detectors, this vulnerability could trigger exponential regex evaluation times, potentially leading to denial of service. DetailsThe vulnerability affects Giskard's punctuation removal transformation used in the text perturbation detection. A regex used to detect URLs and links was vulnerable to catastrophic backtracking that could be triggered by specific patterns in the text. Affected versionGiskard versions prior to 2.15.5 are affected. Users should upgrade to version 2.15.5 or later, which includes a fix for this vulnerability. ImpactThis vulnerability can cause extended computation times or crashes in Giskard when processing text containing certain patterns. CreditThis issue was discovered and reported by GHSL team member @kevinbackhouse (Kevin Backhouse). Affected versions
0.1.2
1.0.0
1.0.0a1
1.0.0a2
1.1.0
1.2.0
1.3.0
1.3.1
1.4.0
1.5.0
1.6.0
1.7.0
+ 92 more Show less
1.7.0a1
1.7.0a2
1.7.0a3
1.7.0a4
1.7.0a5
1.7.0a6
1.7.0a7
1.7.1
1.7.2
1.7.3
1.8.0
1.9.0
1.9.1
1.9.3
1.9.4
2.0.0
2.0.0b1
2.0.0b10
2.0.0b11
2.0.0b12
2.0.0b13
2.0.0b14
2.0.0b16
2.0.0b17
2.0.0b18
2.0.0b19
2.0.0b2
2.0.0b20
2.0.0b22
2.0.0b25
2.0.0b26
2.0.0b27
2.0.0b28
2.0.0b29
2.0.0b3
2.0.0b30
2.0.0b31
2.0.0b32
2.0.0b33
2.0.0b34
2.0.0b4
2.0.0b5
2.0.0b6
2.0.0b7
2.0.0b8
2.0.0b9
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.1.1
2.1.2
2.1.3
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.14.1
2.14.2
2.14.3
2.14.4
2.14.5
2.14.6
2.15.0
2.15.1
2.15.2
2.15.3
2.15.4
2.2.0
2.3.1
2.3.2
2.4.0
2.5.0
2.5.1
2.5.2
2.5.3
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.8.0
2.9.0
2.9.1
Fixed in
2.15.5
References
Updated Jul 07, 2026 · Source: OSV.dev |
2.15.4
patch
Dependencies (36)
+ 28 more |
|
2.15.3
patch
1 CVE
CVE-2024-52524
PYSEC-2026-1403
GHSA-pjwm-cr36-mwv3
Jul 07, 2026
ReDoS in giskard's transformation.py (GHSL-2024-324)
Medium
Network
Low
None
None
ReDoS in Giskard text perturbation detectorA Remote Code Execution (ReDoS) vulnerability was discovered in Giskard component by the GitHub Security Lab team. When processing datasets with specific text patterns with Giskard detectors, this vulnerability could trigger exponential regex evaluation times, potentially leading to denial of service. DetailsThe vulnerability affects Giskard's punctuation removal transformation used in the text perturbation detection. A regex used to detect URLs and links was vulnerable to catastrophic backtracking that could be triggered by specific patterns in the text. Affected versionGiskard versions prior to 2.15.5 are affected. Users should upgrade to version 2.15.5 or later, which includes a fix for this vulnerability. ImpactThis vulnerability can cause extended computation times or crashes in Giskard when processing text containing certain patterns. CreditThis issue was discovered and reported by GHSL team member @kevinbackhouse (Kevin Backhouse). Affected versions
0.1.2
1.0.0
1.0.0a1
1.0.0a2
1.1.0
1.2.0
1.3.0
1.3.1
1.4.0
1.5.0
1.6.0
1.7.0
+ 92 more Show less
1.7.0a1
1.7.0a2
1.7.0a3
1.7.0a4
1.7.0a5
1.7.0a6
1.7.0a7
1.7.1
1.7.2
1.7.3
1.8.0
1.9.0
1.9.1
1.9.3
1.9.4
2.0.0
2.0.0b1
2.0.0b10
2.0.0b11
2.0.0b12
2.0.0b13
2.0.0b14
2.0.0b16
2.0.0b17
2.0.0b18
2.0.0b19
2.0.0b2
2.0.0b20
2.0.0b22
2.0.0b25
2.0.0b26
2.0.0b27
2.0.0b28
2.0.0b29
2.0.0b3
2.0.0b30
2.0.0b31
2.0.0b32
2.0.0b33
2.0.0b34
2.0.0b4
2.0.0b5
2.0.0b6
2.0.0b7
2.0.0b8
2.0.0b9
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.1.1
2.1.2
2.1.3
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.14.1
2.14.2
2.14.3
2.14.4
2.14.5
2.14.6
2.15.0
2.15.1
2.15.2
2.15.3
2.15.4
2.2.0
2.3.1
2.3.2
2.4.0
2.5.0
2.5.1
2.5.2
2.5.3
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.8.0
2.9.0
2.9.1
Fixed in
2.15.5
References
Updated Jul 07, 2026 · Source: OSV.dev |
2.15.3
patch
Dependencies (36)
+ 28 more |
|
2.15.2
patch
1 CVE
CVE-2024-52524
PYSEC-2026-1403
GHSA-pjwm-cr36-mwv3
Jul 07, 2026
ReDoS in giskard's transformation.py (GHSL-2024-324)
Medium
Network
Low
None
None
ReDoS in Giskard text perturbation detectorA Remote Code Execution (ReDoS) vulnerability was discovered in Giskard component by the GitHub Security Lab team. When processing datasets with specific text patterns with Giskard detectors, this vulnerability could trigger exponential regex evaluation times, potentially leading to denial of service. DetailsThe vulnerability affects Giskard's punctuation removal transformation used in the text perturbation detection. A regex used to detect URLs and links was vulnerable to catastrophic backtracking that could be triggered by specific patterns in the text. Affected versionGiskard versions prior to 2.15.5 are affected. Users should upgrade to version 2.15.5 or later, which includes a fix for this vulnerability. ImpactThis vulnerability can cause extended computation times or crashes in Giskard when processing text containing certain patterns. CreditThis issue was discovered and reported by GHSL team member @kevinbackhouse (Kevin Backhouse). Affected versions
0.1.2
1.0.0
1.0.0a1
1.0.0a2
1.1.0
1.2.0
1.3.0
1.3.1
1.4.0
1.5.0
1.6.0
1.7.0
+ 92 more Show less
1.7.0a1
1.7.0a2
1.7.0a3
1.7.0a4
1.7.0a5
1.7.0a6
1.7.0a7
1.7.1
1.7.2
1.7.3
1.8.0
1.9.0
1.9.1
1.9.3
1.9.4
2.0.0
2.0.0b1
2.0.0b10
2.0.0b11
2.0.0b12
2.0.0b13
2.0.0b14
2.0.0b16
2.0.0b17
2.0.0b18
2.0.0b19
2.0.0b2
2.0.0b20
2.0.0b22
2.0.0b25
2.0.0b26
2.0.0b27
2.0.0b28
2.0.0b29
2.0.0b3
2.0.0b30
2.0.0b31
2.0.0b32
2.0.0b33
2.0.0b34
2.0.0b4
2.0.0b5
2.0.0b6
2.0.0b7
2.0.0b8
2.0.0b9
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.1.1
2.1.2
2.1.3
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.14.1
2.14.2
2.14.3
2.14.4
2.14.5
2.14.6
2.15.0
2.15.1
2.15.2
2.15.3
2.15.4
2.2.0
2.3.1
2.3.2
2.4.0
2.5.0
2.5.1
2.5.2
2.5.3
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.8.0
2.9.0
2.9.1
Fixed in
2.15.5
References
Updated Jul 07, 2026 · Source: OSV.dev |
2.15.2
patch
Dependencies (36)
+ 28 more |
|
2.15.1
patch
1 CVE
CVE-2024-52524
PYSEC-2026-1403
GHSA-pjwm-cr36-mwv3
Jul 07, 2026
ReDoS in giskard's transformation.py (GHSL-2024-324)
Medium
Network
Low
None
None
ReDoS in Giskard text perturbation detectorA Remote Code Execution (ReDoS) vulnerability was discovered in Giskard component by the GitHub Security Lab team. When processing datasets with specific text patterns with Giskard detectors, this vulnerability could trigger exponential regex evaluation times, potentially leading to denial of service. DetailsThe vulnerability affects Giskard's punctuation removal transformation used in the text perturbation detection. A regex used to detect URLs and links was vulnerable to catastrophic backtracking that could be triggered by specific patterns in the text. Affected versionGiskard versions prior to 2.15.5 are affected. Users should upgrade to version 2.15.5 or later, which includes a fix for this vulnerability. ImpactThis vulnerability can cause extended computation times or crashes in Giskard when processing text containing certain patterns. CreditThis issue was discovered and reported by GHSL team member @kevinbackhouse (Kevin Backhouse). Affected versions
0.1.2
1.0.0
1.0.0a1
1.0.0a2
1.1.0
1.2.0
1.3.0
1.3.1
1.4.0
1.5.0
1.6.0
1.7.0
+ 92 more Show less
1.7.0a1
1.7.0a2
1.7.0a3
1.7.0a4
1.7.0a5
1.7.0a6
1.7.0a7
1.7.1
1.7.2
1.7.3
1.8.0
1.9.0
1.9.1
1.9.3
1.9.4
2.0.0
2.0.0b1
2.0.0b10
2.0.0b11
2.0.0b12
2.0.0b13
2.0.0b14
2.0.0b16
2.0.0b17
2.0.0b18
2.0.0b19
2.0.0b2
2.0.0b20
2.0.0b22
2.0.0b25
2.0.0b26
2.0.0b27
2.0.0b28
2.0.0b29
2.0.0b3
2.0.0b30
2.0.0b31
2.0.0b32
2.0.0b33
2.0.0b34
2.0.0b4
2.0.0b5
2.0.0b6
2.0.0b7
2.0.0b8
2.0.0b9
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.1.1
2.1.2
2.1.3
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.14.1
2.14.2
2.14.3
2.14.4
2.14.5
2.14.6
2.15.0
2.15.1
2.15.2
2.15.3
2.15.4
2.2.0
2.3.1
2.3.2
2.4.0
2.5.0
2.5.1
2.5.2
2.5.3
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.8.0
2.9.0
2.9.1
Fixed in
2.15.5
References
Updated Jul 07, 2026 · Source: OSV.dev |
2.15.1
patch
Dependencies (36)
+ 28 more |
|
2.15.0
minor
1 CVE
CVE-2024-52524
PYSEC-2026-1403
GHSA-pjwm-cr36-mwv3
Jul 07, 2026
ReDoS in giskard's transformation.py (GHSL-2024-324)
Medium
Network
Low
None
None
ReDoS in Giskard text perturbation detectorA Remote Code Execution (ReDoS) vulnerability was discovered in Giskard component by the GitHub Security Lab team. When processing datasets with specific text patterns with Giskard detectors, this vulnerability could trigger exponential regex evaluation times, potentially leading to denial of service. DetailsThe vulnerability affects Giskard's punctuation removal transformation used in the text perturbation detection. A regex used to detect URLs and links was vulnerable to catastrophic backtracking that could be triggered by specific patterns in the text. Affected versionGiskard versions prior to 2.15.5 are affected. Users should upgrade to version 2.15.5 or later, which includes a fix for this vulnerability. ImpactThis vulnerability can cause extended computation times or crashes in Giskard when processing text containing certain patterns. CreditThis issue was discovered and reported by GHSL team member @kevinbackhouse (Kevin Backhouse). Affected versions
0.1.2
1.0.0
1.0.0a1
1.0.0a2
1.1.0
1.2.0
1.3.0
1.3.1
1.4.0
1.5.0
1.6.0
1.7.0
+ 92 more Show less
1.7.0a1
1.7.0a2
1.7.0a3
1.7.0a4
1.7.0a5
1.7.0a6
1.7.0a7
1.7.1
1.7.2
1.7.3
1.8.0
1.9.0
1.9.1
1.9.3
1.9.4
2.0.0
2.0.0b1
2.0.0b10
2.0.0b11
2.0.0b12
2.0.0b13
2.0.0b14
2.0.0b16
2.0.0b17
2.0.0b18
2.0.0b19
2.0.0b2
2.0.0b20
2.0.0b22
2.0.0b25
2.0.0b26
2.0.0b27
2.0.0b28
2.0.0b29
2.0.0b3
2.0.0b30
2.0.0b31
2.0.0b32
2.0.0b33
2.0.0b34
2.0.0b4
2.0.0b5
2.0.0b6
2.0.0b7
2.0.0b8
2.0.0b9
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.1.1
2.1.2
2.1.3
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.14.1
2.14.2
2.14.3
2.14.4
2.14.5
2.14.6
2.15.0
2.15.1
2.15.2
2.15.3
2.15.4
2.2.0
2.3.1
2.3.2
2.4.0
2.5.0
2.5.1
2.5.2
2.5.3
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.8.0
2.9.0
2.9.1
Fixed in
2.15.5
References
Updated Jul 07, 2026 · Source: OSV.dev |
2.15.0
minor
Dependencies (36)
+ 28 more |
|
2.14.6
patch
1 CVE
CVE-2024-52524
PYSEC-2026-1403
GHSA-pjwm-cr36-mwv3
Jul 07, 2026
ReDoS in giskard's transformation.py (GHSL-2024-324)
Medium
Network
Low
None
None
ReDoS in Giskard text perturbation detectorA Remote Code Execution (ReDoS) vulnerability was discovered in Giskard component by the GitHub Security Lab team. When processing datasets with specific text patterns with Giskard detectors, this vulnerability could trigger exponential regex evaluation times, potentially leading to denial of service. DetailsThe vulnerability affects Giskard's punctuation removal transformation used in the text perturbation detection. A regex used to detect URLs and links was vulnerable to catastrophic backtracking that could be triggered by specific patterns in the text. Affected versionGiskard versions prior to 2.15.5 are affected. Users should upgrade to version 2.15.5 or later, which includes a fix for this vulnerability. ImpactThis vulnerability can cause extended computation times or crashes in Giskard when processing text containing certain patterns. CreditThis issue was discovered and reported by GHSL team member @kevinbackhouse (Kevin Backhouse). Affected versions
0.1.2
1.0.0
1.0.0a1
1.0.0a2
1.1.0
1.2.0
1.3.0
1.3.1
1.4.0
1.5.0
1.6.0
1.7.0
+ 92 more Show less
1.7.0a1
1.7.0a2
1.7.0a3
1.7.0a4
1.7.0a5
1.7.0a6
1.7.0a7
1.7.1
1.7.2
1.7.3
1.8.0
1.9.0
1.9.1
1.9.3
1.9.4
2.0.0
2.0.0b1
2.0.0b10
2.0.0b11
2.0.0b12
2.0.0b13
2.0.0b14
2.0.0b16
2.0.0b17
2.0.0b18
2.0.0b19
2.0.0b2
2.0.0b20
2.0.0b22
2.0.0b25
2.0.0b26
2.0.0b27
2.0.0b28
2.0.0b29
2.0.0b3
2.0.0b30
2.0.0b31
2.0.0b32
2.0.0b33
2.0.0b34
2.0.0b4
2.0.0b5
2.0.0b6
2.0.0b7
2.0.0b8
2.0.0b9
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.1.1
2.1.2
2.1.3
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.14.1
2.14.2
2.14.3
2.14.4
2.14.5
2.14.6
2.15.0
2.15.1
2.15.2
2.15.3
2.15.4
2.2.0
2.3.1
2.3.2
2.4.0
2.5.0
2.5.1
2.5.2
2.5.3
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.8.0
2.9.0
2.9.1
Fixed in
2.15.5
References
Updated Jul 07, 2026 · Source: OSV.dev |
2.14.6
patch
Dependencies (43)
+ 35 more |
|
2.14.5
patch
1 CVE
CVE-2024-52524
PYSEC-2026-1403
GHSA-pjwm-cr36-mwv3
Jul 07, 2026
ReDoS in giskard's transformation.py (GHSL-2024-324)
Medium
Network
Low
None
None
ReDoS in Giskard text perturbation detectorA Remote Code Execution (ReDoS) vulnerability was discovered in Giskard component by the GitHub Security Lab team. When processing datasets with specific text patterns with Giskard detectors, this vulnerability could trigger exponential regex evaluation times, potentially leading to denial of service. DetailsThe vulnerability affects Giskard's punctuation removal transformation used in the text perturbation detection. A regex used to detect URLs and links was vulnerable to catastrophic backtracking that could be triggered by specific patterns in the text. Affected versionGiskard versions prior to 2.15.5 are affected. Users should upgrade to version 2.15.5 or later, which includes a fix for this vulnerability. ImpactThis vulnerability can cause extended computation times or crashes in Giskard when processing text containing certain patterns. CreditThis issue was discovered and reported by GHSL team member @kevinbackhouse (Kevin Backhouse). Affected versions
0.1.2
1.0.0
1.0.0a1
1.0.0a2
1.1.0
1.2.0
1.3.0
1.3.1
1.4.0
1.5.0
1.6.0
1.7.0
+ 92 more Show less
1.7.0a1
1.7.0a2
1.7.0a3
1.7.0a4
1.7.0a5
1.7.0a6
1.7.0a7
1.7.1
1.7.2
1.7.3
1.8.0
1.9.0
1.9.1
1.9.3
1.9.4
2.0.0
2.0.0b1
2.0.0b10
2.0.0b11
2.0.0b12
2.0.0b13
2.0.0b14
2.0.0b16
2.0.0b17
2.0.0b18
2.0.0b19
2.0.0b2
2.0.0b20
2.0.0b22
2.0.0b25
2.0.0b26
2.0.0b27
2.0.0b28
2.0.0b29
2.0.0b3
2.0.0b30
2.0.0b31
2.0.0b32
2.0.0b33
2.0.0b34
2.0.0b4
2.0.0b5
2.0.0b6
2.0.0b7
2.0.0b8
2.0.0b9
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.1.1
2.1.2
2.1.3
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.14.1
2.14.2
2.14.3
2.14.4
2.14.5
2.14.6
2.15.0
2.15.1
2.15.2
2.15.3
2.15.4
2.2.0
2.3.1
2.3.2
2.4.0
2.5.0
2.5.1
2.5.2
2.5.3
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.8.0
2.9.0
2.9.1
Fixed in
2.15.5
References
Updated Jul 07, 2026 · Source: OSV.dev |
2.14.5
patch
Dependencies (43)
+ 35 more |
|
2.14.4
patch
1 CVE
CVE-2024-52524
PYSEC-2026-1403
GHSA-pjwm-cr36-mwv3
Jul 07, 2026
ReDoS in giskard's transformation.py (GHSL-2024-324)
Medium
Network
Low
None
None
ReDoS in Giskard text perturbation detectorA Remote Code Execution (ReDoS) vulnerability was discovered in Giskard component by the GitHub Security Lab team. When processing datasets with specific text patterns with Giskard detectors, this vulnerability could trigger exponential regex evaluation times, potentially leading to denial of service. DetailsThe vulnerability affects Giskard's punctuation removal transformation used in the text perturbation detection. A regex used to detect URLs and links was vulnerable to catastrophic backtracking that could be triggered by specific patterns in the text. Affected versionGiskard versions prior to 2.15.5 are affected. Users should upgrade to version 2.15.5 or later, which includes a fix for this vulnerability. ImpactThis vulnerability can cause extended computation times or crashes in Giskard when processing text containing certain patterns. CreditThis issue was discovered and reported by GHSL team member @kevinbackhouse (Kevin Backhouse). Affected versions
0.1.2
1.0.0
1.0.0a1
1.0.0a2
1.1.0
1.2.0
1.3.0
1.3.1
1.4.0
1.5.0
1.6.0
1.7.0
+ 92 more Show less
1.7.0a1
1.7.0a2
1.7.0a3
1.7.0a4
1.7.0a5
1.7.0a6
1.7.0a7
1.7.1
1.7.2
1.7.3
1.8.0
1.9.0
1.9.1
1.9.3
1.9.4
2.0.0
2.0.0b1
2.0.0b10
2.0.0b11
2.0.0b12
2.0.0b13
2.0.0b14
2.0.0b16
2.0.0b17
2.0.0b18
2.0.0b19
2.0.0b2
2.0.0b20
2.0.0b22
2.0.0b25
2.0.0b26
2.0.0b27
2.0.0b28
2.0.0b29
2.0.0b3
2.0.0b30
2.0.0b31
2.0.0b32
2.0.0b33
2.0.0b34
2.0.0b4
2.0.0b5
2.0.0b6
2.0.0b7
2.0.0b8
2.0.0b9
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.1.1
2.1.2
2.1.3
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.14.1
2.14.2
2.14.3
2.14.4
2.14.5
2.14.6
2.15.0
2.15.1
2.15.2
2.15.3
2.15.4
2.2.0
2.3.1
2.3.2
2.4.0
2.5.0
2.5.1
2.5.2
2.5.3
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.8.0
2.9.0
2.9.1
Fixed in
2.15.5
References
Updated Jul 07, 2026 · Source: OSV.dev |
2.14.4
patch
Dependencies (44)
+ 36 more |
|
2.14.3
patch
1 CVE
CVE-2024-52524
PYSEC-2026-1403
GHSA-pjwm-cr36-mwv3
Jul 07, 2026
ReDoS in giskard's transformation.py (GHSL-2024-324)
Medium
Network
Low
None
None
ReDoS in Giskard text perturbation detectorA Remote Code Execution (ReDoS) vulnerability was discovered in Giskard component by the GitHub Security Lab team. When processing datasets with specific text patterns with Giskard detectors, this vulnerability could trigger exponential regex evaluation times, potentially leading to denial of service. DetailsThe vulnerability affects Giskard's punctuation removal transformation used in the text perturbation detection. A regex used to detect URLs and links was vulnerable to catastrophic backtracking that could be triggered by specific patterns in the text. Affected versionGiskard versions prior to 2.15.5 are affected. Users should upgrade to version 2.15.5 or later, which includes a fix for this vulnerability. ImpactThis vulnerability can cause extended computation times or crashes in Giskard when processing text containing certain patterns. CreditThis issue was discovered and reported by GHSL team member @kevinbackhouse (Kevin Backhouse). Affected versions
0.1.2
1.0.0
1.0.0a1
1.0.0a2
1.1.0
1.2.0
1.3.0
1.3.1
1.4.0
1.5.0
1.6.0
1.7.0
+ 92 more Show less
1.7.0a1
1.7.0a2
1.7.0a3
1.7.0a4
1.7.0a5
1.7.0a6
1.7.0a7
1.7.1
1.7.2
1.7.3
1.8.0
1.9.0
1.9.1
1.9.3
1.9.4
2.0.0
2.0.0b1
2.0.0b10
2.0.0b11
2.0.0b12
2.0.0b13
2.0.0b14
2.0.0b16
2.0.0b17
2.0.0b18
2.0.0b19
2.0.0b2
2.0.0b20
2.0.0b22
2.0.0b25
2.0.0b26
2.0.0b27
2.0.0b28
2.0.0b29
2.0.0b3
2.0.0b30
2.0.0b31
2.0.0b32
2.0.0b33
2.0.0b34
2.0.0b4
2.0.0b5
2.0.0b6
2.0.0b7
2.0.0b8
2.0.0b9
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.1.1
2.1.2
2.1.3
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.14.1
2.14.2
2.14.3
2.14.4
2.14.5
2.14.6
2.15.0
2.15.1
2.15.2
2.15.3
2.15.4
2.2.0
2.3.1
2.3.2
2.4.0
2.5.0
2.5.1
2.5.2
2.5.3
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.8.0
2.9.0
2.9.1
Fixed in
2.15.5
References
Updated Jul 07, 2026 · Source: OSV.dev |
2.14.3
patch
Dependencies (44)
+ 36 more |
|
2.14.2
patch
1 CVE
CVE-2024-52524
PYSEC-2026-1403
GHSA-pjwm-cr36-mwv3
Jul 07, 2026
ReDoS in giskard's transformation.py (GHSL-2024-324)
Medium
Network
Low
None
None
ReDoS in Giskard text perturbation detectorA Remote Code Execution (ReDoS) vulnerability was discovered in Giskard component by the GitHub Security Lab team. When processing datasets with specific text patterns with Giskard detectors, this vulnerability could trigger exponential regex evaluation times, potentially leading to denial of service. DetailsThe vulnerability affects Giskard's punctuation removal transformation used in the text perturbation detection. A regex used to detect URLs and links was vulnerable to catastrophic backtracking that could be triggered by specific patterns in the text. Affected versionGiskard versions prior to 2.15.5 are affected. Users should upgrade to version 2.15.5 or later, which includes a fix for this vulnerability. ImpactThis vulnerability can cause extended computation times or crashes in Giskard when processing text containing certain patterns. CreditThis issue was discovered and reported by GHSL team member @kevinbackhouse (Kevin Backhouse). Affected versions
0.1.2
1.0.0
1.0.0a1
1.0.0a2
1.1.0
1.2.0
1.3.0
1.3.1
1.4.0
1.5.0
1.6.0
1.7.0
+ 92 more Show less
1.7.0a1
1.7.0a2
1.7.0a3
1.7.0a4
1.7.0a5
1.7.0a6
1.7.0a7
1.7.1
1.7.2
1.7.3
1.8.0
1.9.0
1.9.1
1.9.3
1.9.4
2.0.0
2.0.0b1
2.0.0b10
2.0.0b11
2.0.0b12
2.0.0b13
2.0.0b14
2.0.0b16
2.0.0b17
2.0.0b18
2.0.0b19
2.0.0b2
2.0.0b20
2.0.0b22
2.0.0b25
2.0.0b26
2.0.0b27
2.0.0b28
2.0.0b29
2.0.0b3
2.0.0b30
2.0.0b31
2.0.0b32
2.0.0b33
2.0.0b34
2.0.0b4
2.0.0b5
2.0.0b6
2.0.0b7
2.0.0b8
2.0.0b9
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.1.1
2.1.2
2.1.3
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.14.1
2.14.2
2.14.3
2.14.4
2.14.5
2.14.6
2.15.0
2.15.1
2.15.2
2.15.3
2.15.4
2.2.0
2.3.1
2.3.2
2.4.0
2.5.0
2.5.1
2.5.2
2.5.3
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.8.0
2.9.0
2.9.1
Fixed in
2.15.5
References
Updated Jul 07, 2026 · Source: OSV.dev |
2.14.2
patch
Dependencies (44)
+ 36 more |
|
2.14.1
patch
1 CVE
CVE-2024-52524
PYSEC-2026-1403
GHSA-pjwm-cr36-mwv3
Jul 07, 2026
ReDoS in giskard's transformation.py (GHSL-2024-324)
Medium
Network
Low
None
None
ReDoS in Giskard text perturbation detectorA Remote Code Execution (ReDoS) vulnerability was discovered in Giskard component by the GitHub Security Lab team. When processing datasets with specific text patterns with Giskard detectors, this vulnerability could trigger exponential regex evaluation times, potentially leading to denial of service. DetailsThe vulnerability affects Giskard's punctuation removal transformation used in the text perturbation detection. A regex used to detect URLs and links was vulnerable to catastrophic backtracking that could be triggered by specific patterns in the text. Affected versionGiskard versions prior to 2.15.5 are affected. Users should upgrade to version 2.15.5 or later, which includes a fix for this vulnerability. ImpactThis vulnerability can cause extended computation times or crashes in Giskard when processing text containing certain patterns. CreditThis issue was discovered and reported by GHSL team member @kevinbackhouse (Kevin Backhouse). Affected versions
0.1.2
1.0.0
1.0.0a1
1.0.0a2
1.1.0
1.2.0
1.3.0
1.3.1
1.4.0
1.5.0
1.6.0
1.7.0
+ 92 more Show less
1.7.0a1
1.7.0a2
1.7.0a3
1.7.0a4
1.7.0a5
1.7.0a6
1.7.0a7
1.7.1
1.7.2
1.7.3
1.8.0
1.9.0
1.9.1
1.9.3
1.9.4
2.0.0
2.0.0b1
2.0.0b10
2.0.0b11
2.0.0b12
2.0.0b13
2.0.0b14
2.0.0b16
2.0.0b17
2.0.0b18
2.0.0b19
2.0.0b2
2.0.0b20
2.0.0b22
2.0.0b25
2.0.0b26
2.0.0b27
2.0.0b28
2.0.0b29
2.0.0b3
2.0.0b30
2.0.0b31
2.0.0b32
2.0.0b33
2.0.0b34
2.0.0b4
2.0.0b5
2.0.0b6
2.0.0b7
2.0.0b8
2.0.0b9
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.1.1
2.1.2
2.1.3
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.14.1
2.14.2
2.14.3
2.14.4
2.14.5
2.14.6
2.15.0
2.15.1
2.15.2
2.15.3
2.15.4
2.2.0
2.3.1
2.3.2
2.4.0
2.5.0
2.5.1
2.5.2
2.5.3
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.8.0
2.9.0
2.9.1
Fixed in
2.15.5
References
Updated Jul 07, 2026 · Source: OSV.dev |
2.14.1
patch
Dependencies (44)
+ 36 more |
|
2.14.0
minor
1 CVE
CVE-2024-52524
PYSEC-2026-1403
GHSA-pjwm-cr36-mwv3
Jul 07, 2026
ReDoS in giskard's transformation.py (GHSL-2024-324)
Medium
Network
Low
None
None
ReDoS in Giskard text perturbation detectorA Remote Code Execution (ReDoS) vulnerability was discovered in Giskard component by the GitHub Security Lab team. When processing datasets with specific text patterns with Giskard detectors, this vulnerability could trigger exponential regex evaluation times, potentially leading to denial of service. DetailsThe vulnerability affects Giskard's punctuation removal transformation used in the text perturbation detection. A regex used to detect URLs and links was vulnerable to catastrophic backtracking that could be triggered by specific patterns in the text. Affected versionGiskard versions prior to 2.15.5 are affected. Users should upgrade to version 2.15.5 or later, which includes a fix for this vulnerability. ImpactThis vulnerability can cause extended computation times or crashes in Giskard when processing text containing certain patterns. CreditThis issue was discovered and reported by GHSL team member @kevinbackhouse (Kevin Backhouse). Affected versions
0.1.2
1.0.0
1.0.0a1
1.0.0a2
1.1.0
1.2.0
1.3.0
1.3.1
1.4.0
1.5.0
1.6.0
1.7.0
+ 92 more Show less
1.7.0a1
1.7.0a2
1.7.0a3
1.7.0a4
1.7.0a5
1.7.0a6
1.7.0a7
1.7.1
1.7.2
1.7.3
1.8.0
1.9.0
1.9.1
1.9.3
1.9.4
2.0.0
2.0.0b1
2.0.0b10
2.0.0b11
2.0.0b12
2.0.0b13
2.0.0b14
2.0.0b16
2.0.0b17
2.0.0b18
2.0.0b19
2.0.0b2
2.0.0b20
2.0.0b22
2.0.0b25
2.0.0b26
2.0.0b27
2.0.0b28
2.0.0b29
2.0.0b3
2.0.0b30
2.0.0b31
2.0.0b32
2.0.0b33
2.0.0b34
2.0.0b4
2.0.0b5
2.0.0b6
2.0.0b7
2.0.0b8
2.0.0b9
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.1.1
2.1.2
2.1.3
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.14.1
2.14.2
2.14.3
2.14.4
2.14.5
2.14.6
2.15.0
2.15.1
2.15.2
2.15.3
2.15.4
2.2.0
2.3.1
2.3.2
2.4.0
2.5.0
2.5.1
2.5.2
2.5.3
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.8.0
2.9.0
2.9.1
Fixed in
2.15.5
References
Updated Jul 07, 2026 · Source: OSV.dev |
2.14.0
minor
Dependencies (44)
+ 36 more |
|
2.13.0
minor
1 CVE
CVE-2024-52524
PYSEC-2026-1403
GHSA-pjwm-cr36-mwv3
Jul 07, 2026
ReDoS in giskard's transformation.py (GHSL-2024-324)
Medium
Network
Low
None
None
ReDoS in Giskard text perturbation detectorA Remote Code Execution (ReDoS) vulnerability was discovered in Giskard component by the GitHub Security Lab team. When processing datasets with specific text patterns with Giskard detectors, this vulnerability could trigger exponential regex evaluation times, potentially leading to denial of service. DetailsThe vulnerability affects Giskard's punctuation removal transformation used in the text perturbation detection. A regex used to detect URLs and links was vulnerable to catastrophic backtracking that could be triggered by specific patterns in the text. Affected versionGiskard versions prior to 2.15.5 are affected. Users should upgrade to version 2.15.5 or later, which includes a fix for this vulnerability. ImpactThis vulnerability can cause extended computation times or crashes in Giskard when processing text containing certain patterns. CreditThis issue was discovered and reported by GHSL team member @kevinbackhouse (Kevin Backhouse). Affected versions
0.1.2
1.0.0
1.0.0a1
1.0.0a2
1.1.0
1.2.0
1.3.0
1.3.1
1.4.0
1.5.0
1.6.0
1.7.0
+ 92 more Show less
1.7.0a1
1.7.0a2
1.7.0a3
1.7.0a4
1.7.0a5
1.7.0a6
1.7.0a7
1.7.1
1.7.2
1.7.3
1.8.0
1.9.0
1.9.1
1.9.3
1.9.4
2.0.0
2.0.0b1
2.0.0b10
2.0.0b11
2.0.0b12
2.0.0b13
2.0.0b14
2.0.0b16
2.0.0b17
2.0.0b18
2.0.0b19
2.0.0b2
2.0.0b20
2.0.0b22
2.0.0b25
2.0.0b26
2.0.0b27
2.0.0b28
2.0.0b29
2.0.0b3
2.0.0b30
2.0.0b31
2.0.0b32
2.0.0b33
2.0.0b34
2.0.0b4
2.0.0b5
2.0.0b6
2.0.0b7
2.0.0b8
2.0.0b9
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.1.1
2.1.2
2.1.3
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.14.1
2.14.2
2.14.3
2.14.4
2.14.5
2.14.6
2.15.0
2.15.1
2.15.2
2.15.3
2.15.4
2.2.0
2.3.1
2.3.2
2.4.0
2.5.0
2.5.1
2.5.2
2.5.3
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.8.0
2.9.0
2.9.1
Fixed in
2.15.5
References
Updated Jul 07, 2026 · Source: OSV.dev |
2.13.0
minor
Dependencies (44)
+ 36 more |
|
2.12.0
minor
1 CVE
CVE-2024-52524
PYSEC-2026-1403
GHSA-pjwm-cr36-mwv3
Jul 07, 2026
ReDoS in giskard's transformation.py (GHSL-2024-324)
Medium
Network
Low
None
None
ReDoS in Giskard text perturbation detectorA Remote Code Execution (ReDoS) vulnerability was discovered in Giskard component by the GitHub Security Lab team. When processing datasets with specific text patterns with Giskard detectors, this vulnerability could trigger exponential regex evaluation times, potentially leading to denial of service. DetailsThe vulnerability affects Giskard's punctuation removal transformation used in the text perturbation detection. A regex used to detect URLs and links was vulnerable to catastrophic backtracking that could be triggered by specific patterns in the text. Affected versionGiskard versions prior to 2.15.5 are affected. Users should upgrade to version 2.15.5 or later, which includes a fix for this vulnerability. ImpactThis vulnerability can cause extended computation times or crashes in Giskard when processing text containing certain patterns. CreditThis issue was discovered and reported by GHSL team member @kevinbackhouse (Kevin Backhouse). Affected versions
0.1.2
1.0.0
1.0.0a1
1.0.0a2
1.1.0
1.2.0
1.3.0
1.3.1
1.4.0
1.5.0
1.6.0
1.7.0
+ 92 more Show less
1.7.0a1
1.7.0a2
1.7.0a3
1.7.0a4
1.7.0a5
1.7.0a6
1.7.0a7
1.7.1
1.7.2
1.7.3
1.8.0
1.9.0
1.9.1
1.9.3
1.9.4
2.0.0
2.0.0b1
2.0.0b10
2.0.0b11
2.0.0b12
2.0.0b13
2.0.0b14
2.0.0b16
2.0.0b17
2.0.0b18
2.0.0b19
2.0.0b2
2.0.0b20
2.0.0b22
2.0.0b25
2.0.0b26
2.0.0b27
2.0.0b28
2.0.0b29
2.0.0b3
2.0.0b30
2.0.0b31
2.0.0b32
2.0.0b33
2.0.0b34
2.0.0b4
2.0.0b5
2.0.0b6
2.0.0b7
2.0.0b8
2.0.0b9
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.1.1
2.1.2
2.1.3
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.14.1
2.14.2
2.14.3
2.14.4
2.14.5
2.14.6
2.15.0
2.15.1
2.15.2
2.15.3
2.15.4
2.2.0
2.3.1
2.3.2
2.4.0
2.5.0
2.5.1
2.5.2
2.5.3
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.8.0
2.9.0
2.9.1
Fixed in
2.15.5
References
Updated Jul 07, 2026 · Source: OSV.dev |
2.12.0
minor
Dependencies (44)
+ 36 more |
|
2.11.0
minor
1 CVE
CVE-2024-52524
PYSEC-2026-1403
GHSA-pjwm-cr36-mwv3
Jul 07, 2026
ReDoS in giskard's transformation.py (GHSL-2024-324)
Medium
Network
Low
None
None
ReDoS in Giskard text perturbation detectorA Remote Code Execution (ReDoS) vulnerability was discovered in Giskard component by the GitHub Security Lab team. When processing datasets with specific text patterns with Giskard detectors, this vulnerability could trigger exponential regex evaluation times, potentially leading to denial of service. DetailsThe vulnerability affects Giskard's punctuation removal transformation used in the text perturbation detection. A regex used to detect URLs and links was vulnerable to catastrophic backtracking that could be triggered by specific patterns in the text. Affected versionGiskard versions prior to 2.15.5 are affected. Users should upgrade to version 2.15.5 or later, which includes a fix for this vulnerability. ImpactThis vulnerability can cause extended computation times or crashes in Giskard when processing text containing certain patterns. CreditThis issue was discovered and reported by GHSL team member @kevinbackhouse (Kevin Backhouse). Affected versions
0.1.2
1.0.0
1.0.0a1
1.0.0a2
1.1.0
1.2.0
1.3.0
1.3.1
1.4.0
1.5.0
1.6.0
1.7.0
+ 92 more Show less
1.7.0a1
1.7.0a2
1.7.0a3
1.7.0a4
1.7.0a5
1.7.0a6
1.7.0a7
1.7.1
1.7.2
1.7.3
1.8.0
1.9.0
1.9.1
1.9.3
1.9.4
2.0.0
2.0.0b1
2.0.0b10
2.0.0b11
2.0.0b12
2.0.0b13
2.0.0b14
2.0.0b16
2.0.0b17
2.0.0b18
2.0.0b19
2.0.0b2
2.0.0b20
2.0.0b22
2.0.0b25
2.0.0b26
2.0.0b27
2.0.0b28
2.0.0b29
2.0.0b3
2.0.0b30
2.0.0b31
2.0.0b32
2.0.0b33
2.0.0b34
2.0.0b4
2.0.0b5
2.0.0b6
2.0.0b7
2.0.0b8
2.0.0b9
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.1.1
2.1.2
2.1.3
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.14.1
2.14.2
2.14.3
2.14.4
2.14.5
2.14.6
2.15.0
2.15.1
2.15.2
2.15.3
2.15.4
2.2.0
2.3.1
2.3.2
2.4.0
2.5.0
2.5.1
2.5.2
2.5.3
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.8.0
2.9.0
2.9.1
Fixed in
2.15.5
References
Updated Jul 07, 2026 · Source: OSV.dev |
2.11.0
minor
Dependencies (43)
+ 35 more |
|
2.10.0
minor
1 CVE
CVE-2024-52524
PYSEC-2026-1403
GHSA-pjwm-cr36-mwv3
Jul 07, 2026
ReDoS in giskard's transformation.py (GHSL-2024-324)
Medium
Network
Low
None
None
ReDoS in Giskard text perturbation detectorA Remote Code Execution (ReDoS) vulnerability was discovered in Giskard component by the GitHub Security Lab team. When processing datasets with specific text patterns with Giskard detectors, this vulnerability could trigger exponential regex evaluation times, potentially leading to denial of service. DetailsThe vulnerability affects Giskard's punctuation removal transformation used in the text perturbation detection. A regex used to detect URLs and links was vulnerable to catastrophic backtracking that could be triggered by specific patterns in the text. Affected versionGiskard versions prior to 2.15.5 are affected. Users should upgrade to version 2.15.5 or later, which includes a fix for this vulnerability. ImpactThis vulnerability can cause extended computation times or crashes in Giskard when processing text containing certain patterns. CreditThis issue was discovered and reported by GHSL team member @kevinbackhouse (Kevin Backhouse). Affected versions
0.1.2
1.0.0
1.0.0a1
1.0.0a2
1.1.0
1.2.0
1.3.0
1.3.1
1.4.0
1.5.0
1.6.0
1.7.0
+ 92 more Show less
1.7.0a1
1.7.0a2
1.7.0a3
1.7.0a4
1.7.0a5
1.7.0a6
1.7.0a7
1.7.1
1.7.2
1.7.3
1.8.0
1.9.0
1.9.1
1.9.3
1.9.4
2.0.0
2.0.0b1
2.0.0b10
2.0.0b11
2.0.0b12
2.0.0b13
2.0.0b14
2.0.0b16
2.0.0b17
2.0.0b18
2.0.0b19
2.0.0b2
2.0.0b20
2.0.0b22
2.0.0b25
2.0.0b26
2.0.0b27
2.0.0b28
2.0.0b29
2.0.0b3
2.0.0b30
2.0.0b31
2.0.0b32
2.0.0b33
2.0.0b34
2.0.0b4
2.0.0b5
2.0.0b6
2.0.0b7
2.0.0b8
2.0.0b9
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.1.1
2.1.2
2.1.3
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.14.1
2.14.2
2.14.3
2.14.4
2.14.5
2.14.6
2.15.0
2.15.1
2.15.2
2.15.3
2.15.4
2.2.0
2.3.1
2.3.2
2.4.0
2.5.0
2.5.1
2.5.2
2.5.3
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.8.0
2.9.0
2.9.1
Fixed in
2.15.5
References
Updated Jul 07, 2026 · Source: OSV.dev |
2.10.0
minor
Dependencies (42)
+ 34 more |
|
2.9.1
patch
1 CVE
CVE-2024-52524
PYSEC-2026-1403
GHSA-pjwm-cr36-mwv3
Jul 07, 2026
ReDoS in giskard's transformation.py (GHSL-2024-324)
Medium
Network
Low
None
None
ReDoS in Giskard text perturbation detectorA Remote Code Execution (ReDoS) vulnerability was discovered in Giskard component by the GitHub Security Lab team. When processing datasets with specific text patterns with Giskard detectors, this vulnerability could trigger exponential regex evaluation times, potentially leading to denial of service. DetailsThe vulnerability affects Giskard's punctuation removal transformation used in the text perturbation detection. A regex used to detect URLs and links was vulnerable to catastrophic backtracking that could be triggered by specific patterns in the text. Affected versionGiskard versions prior to 2.15.5 are affected. Users should upgrade to version 2.15.5 or later, which includes a fix for this vulnerability. ImpactThis vulnerability can cause extended computation times or crashes in Giskard when processing text containing certain patterns. CreditThis issue was discovered and reported by GHSL team member @kevinbackhouse (Kevin Backhouse). Affected versions
0.1.2
1.0.0
1.0.0a1
1.0.0a2
1.1.0
1.2.0
1.3.0
1.3.1
1.4.0
1.5.0
1.6.0
1.7.0
+ 92 more Show less
1.7.0a1
1.7.0a2
1.7.0a3
1.7.0a4
1.7.0a5
1.7.0a6
1.7.0a7
1.7.1
1.7.2
1.7.3
1.8.0
1.9.0
1.9.1
1.9.3
1.9.4
2.0.0
2.0.0b1
2.0.0b10
2.0.0b11
2.0.0b12
2.0.0b13
2.0.0b14
2.0.0b16
2.0.0b17
2.0.0b18
2.0.0b19
2.0.0b2
2.0.0b20
2.0.0b22
2.0.0b25
2.0.0b26
2.0.0b27
2.0.0b28
2.0.0b29
2.0.0b3
2.0.0b30
2.0.0b31
2.0.0b32
2.0.0b33
2.0.0b34
2.0.0b4
2.0.0b5
2.0.0b6
2.0.0b7
2.0.0b8
2.0.0b9
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.1.1
2.1.2
2.1.3
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.14.1
2.14.2
2.14.3
2.14.4
2.14.5
2.14.6
2.15.0
2.15.1
2.15.2
2.15.3
2.15.4
2.2.0
2.3.1
2.3.2
2.4.0
2.5.0
2.5.1
2.5.2
2.5.3
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.8.0
2.9.0
2.9.1
Fixed in
2.15.5
References
Updated Jul 07, 2026 · Source: OSV.dev |
2.9.1
patch
Dependencies (42)
+ 34 more |
|
2.9.0
minor
1 CVE
CVE-2024-52524
PYSEC-2026-1403
GHSA-pjwm-cr36-mwv3
Jul 07, 2026
ReDoS in giskard's transformation.py (GHSL-2024-324)
Medium
Network
Low
None
None
ReDoS in Giskard text perturbation detectorA Remote Code Execution (ReDoS) vulnerability was discovered in Giskard component by the GitHub Security Lab team. When processing datasets with specific text patterns with Giskard detectors, this vulnerability could trigger exponential regex evaluation times, potentially leading to denial of service. DetailsThe vulnerability affects Giskard's punctuation removal transformation used in the text perturbation detection. A regex used to detect URLs and links was vulnerable to catastrophic backtracking that could be triggered by specific patterns in the text. Affected versionGiskard versions prior to 2.15.5 are affected. Users should upgrade to version 2.15.5 or later, which includes a fix for this vulnerability. ImpactThis vulnerability can cause extended computation times or crashes in Giskard when processing text containing certain patterns. CreditThis issue was discovered and reported by GHSL team member @kevinbackhouse (Kevin Backhouse). Affected versions
0.1.2
1.0.0
1.0.0a1
1.0.0a2
1.1.0
1.2.0
1.3.0
1.3.1
1.4.0
1.5.0
1.6.0
1.7.0
+ 92 more Show less
1.7.0a1
1.7.0a2
1.7.0a3
1.7.0a4
1.7.0a5
1.7.0a6
1.7.0a7
1.7.1
1.7.2
1.7.3
1.8.0
1.9.0
1.9.1
1.9.3
1.9.4
2.0.0
2.0.0b1
2.0.0b10
2.0.0b11
2.0.0b12
2.0.0b13
2.0.0b14
2.0.0b16
2.0.0b17
2.0.0b18
2.0.0b19
2.0.0b2
2.0.0b20
2.0.0b22
2.0.0b25
2.0.0b26
2.0.0b27
2.0.0b28
2.0.0b29
2.0.0b3
2.0.0b30
2.0.0b31
2.0.0b32
2.0.0b33
2.0.0b34
2.0.0b4
2.0.0b5
2.0.0b6
2.0.0b7
2.0.0b8
2.0.0b9
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.1.1
2.1.2
2.1.3
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.14.1
2.14.2
2.14.3
2.14.4
2.14.5
2.14.6
2.15.0
2.15.1
2.15.2
2.15.3
2.15.4
2.2.0
2.3.1
2.3.2
2.4.0
2.5.0
2.5.1
2.5.2
2.5.3
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.8.0
2.9.0
2.9.1
Fixed in
2.15.5
References
Updated Jul 07, 2026 · Source: OSV.dev |
2.9.0
minor
Dependencies (42)
+ 34 more |
|
2.8.0
minor
1 CVE
CVE-2024-52524
PYSEC-2026-1403
GHSA-pjwm-cr36-mwv3
Jul 07, 2026
ReDoS in giskard's transformation.py (GHSL-2024-324)
Medium
Network
Low
None
None
ReDoS in Giskard text perturbation detectorA Remote Code Execution (ReDoS) vulnerability was discovered in Giskard component by the GitHub Security Lab team. When processing datasets with specific text patterns with Giskard detectors, this vulnerability could trigger exponential regex evaluation times, potentially leading to denial of service. DetailsThe vulnerability affects Giskard's punctuation removal transformation used in the text perturbation detection. A regex used to detect URLs and links was vulnerable to catastrophic backtracking that could be triggered by specific patterns in the text. Affected versionGiskard versions prior to 2.15.5 are affected. Users should upgrade to version 2.15.5 or later, which includes a fix for this vulnerability. ImpactThis vulnerability can cause extended computation times or crashes in Giskard when processing text containing certain patterns. CreditThis issue was discovered and reported by GHSL team member @kevinbackhouse (Kevin Backhouse). Affected versions
0.1.2
1.0.0
1.0.0a1
1.0.0a2
1.1.0
1.2.0
1.3.0
1.3.1
1.4.0
1.5.0
1.6.0
1.7.0
+ 92 more Show less
1.7.0a1
1.7.0a2
1.7.0a3
1.7.0a4
1.7.0a5
1.7.0a6
1.7.0a7
1.7.1
1.7.2
1.7.3
1.8.0
1.9.0
1.9.1
1.9.3
1.9.4
2.0.0
2.0.0b1
2.0.0b10
2.0.0b11
2.0.0b12
2.0.0b13
2.0.0b14
2.0.0b16
2.0.0b17
2.0.0b18
2.0.0b19
2.0.0b2
2.0.0b20
2.0.0b22
2.0.0b25
2.0.0b26
2.0.0b27
2.0.0b28
2.0.0b29
2.0.0b3
2.0.0b30
2.0.0b31
2.0.0b32
2.0.0b33
2.0.0b34
2.0.0b4
2.0.0b5
2.0.0b6
2.0.0b7
2.0.0b8
2.0.0b9
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.1.1
2.1.2
2.1.3
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.14.1
2.14.2
2.14.3
2.14.4
2.14.5
2.14.6
2.15.0
2.15.1
2.15.2
2.15.3
2.15.4
2.2.0
2.3.1
2.3.2
2.4.0
2.5.0
2.5.1
2.5.2
2.5.3
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.8.0
2.9.0
2.9.1
Fixed in
2.15.5
References
Updated Jul 07, 2026 · Source: OSV.dev |
2.8.0
minor
Dependencies (43)
+ 35 more |
|
2.7.7
patch
1 CVE
CVE-2024-52524
PYSEC-2026-1403
GHSA-pjwm-cr36-mwv3
Jul 07, 2026
ReDoS in giskard's transformation.py (GHSL-2024-324)
Medium
Network
Low
None
None
ReDoS in Giskard text perturbation detectorA Remote Code Execution (ReDoS) vulnerability was discovered in Giskard component by the GitHub Security Lab team. When processing datasets with specific text patterns with Giskard detectors, this vulnerability could trigger exponential regex evaluation times, potentially leading to denial of service. DetailsThe vulnerability affects Giskard's punctuation removal transformation used in the text perturbation detection. A regex used to detect URLs and links was vulnerable to catastrophic backtracking that could be triggered by specific patterns in the text. Affected versionGiskard versions prior to 2.15.5 are affected. Users should upgrade to version 2.15.5 or later, which includes a fix for this vulnerability. ImpactThis vulnerability can cause extended computation times or crashes in Giskard when processing text containing certain patterns. CreditThis issue was discovered and reported by GHSL team member @kevinbackhouse (Kevin Backhouse). Affected versions
0.1.2
1.0.0
1.0.0a1
1.0.0a2
1.1.0
1.2.0
1.3.0
1.3.1
1.4.0
1.5.0
1.6.0
1.7.0
+ 92 more Show less
1.7.0a1
1.7.0a2
1.7.0a3
1.7.0a4
1.7.0a5
1.7.0a6
1.7.0a7
1.7.1
1.7.2
1.7.3
1.8.0
1.9.0
1.9.1
1.9.3
1.9.4
2.0.0
2.0.0b1
2.0.0b10
2.0.0b11
2.0.0b12
2.0.0b13
2.0.0b14
2.0.0b16
2.0.0b17
2.0.0b18
2.0.0b19
2.0.0b2
2.0.0b20
2.0.0b22
2.0.0b25
2.0.0b26
2.0.0b27
2.0.0b28
2.0.0b29
2.0.0b3
2.0.0b30
2.0.0b31
2.0.0b32
2.0.0b33
2.0.0b34
2.0.0b4
2.0.0b5
2.0.0b6
2.0.0b7
2.0.0b8
2.0.0b9
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.1.1
2.1.2
2.1.3
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.14.1
2.14.2
2.14.3
2.14.4
2.14.5
2.14.6
2.15.0
2.15.1
2.15.2
2.15.3
2.15.4
2.2.0
2.3.1
2.3.2
2.4.0
2.5.0
2.5.1
2.5.2
2.5.3
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.8.0
2.9.0
2.9.1
Fixed in
2.15.5
References
Updated Jul 07, 2026 · Source: OSV.dev |
2.7.7
patch
Dependencies (41)
+ 33 more |
|
2.7.6
patch
1 CVE
CVE-2024-52524
PYSEC-2026-1403
GHSA-pjwm-cr36-mwv3
Jul 07, 2026
ReDoS in giskard's transformation.py (GHSL-2024-324)
Medium
Network
Low
None
None
ReDoS in Giskard text perturbation detectorA Remote Code Execution (ReDoS) vulnerability was discovered in Giskard component by the GitHub Security Lab team. When processing datasets with specific text patterns with Giskard detectors, this vulnerability could trigger exponential regex evaluation times, potentially leading to denial of service. DetailsThe vulnerability affects Giskard's punctuation removal transformation used in the text perturbation detection. A regex used to detect URLs and links was vulnerable to catastrophic backtracking that could be triggered by specific patterns in the text. Affected versionGiskard versions prior to 2.15.5 are affected. Users should upgrade to version 2.15.5 or later, which includes a fix for this vulnerability. ImpactThis vulnerability can cause extended computation times or crashes in Giskard when processing text containing certain patterns. CreditThis issue was discovered and reported by GHSL team member @kevinbackhouse (Kevin Backhouse). Affected versions
0.1.2
1.0.0
1.0.0a1
1.0.0a2
1.1.0
1.2.0
1.3.0
1.3.1
1.4.0
1.5.0
1.6.0
1.7.0
+ 92 more Show less
1.7.0a1
1.7.0a2
1.7.0a3
1.7.0a4
1.7.0a5
1.7.0a6
1.7.0a7
1.7.1
1.7.2
1.7.3
1.8.0
1.9.0
1.9.1
1.9.3
1.9.4
2.0.0
2.0.0b1
2.0.0b10
2.0.0b11
2.0.0b12
2.0.0b13
2.0.0b14
2.0.0b16
2.0.0b17
2.0.0b18
2.0.0b19
2.0.0b2
2.0.0b20
2.0.0b22
2.0.0b25
2.0.0b26
2.0.0b27
2.0.0b28
2.0.0b29
2.0.0b3
2.0.0b30
2.0.0b31
2.0.0b32
2.0.0b33
2.0.0b34
2.0.0b4
2.0.0b5
2.0.0b6
2.0.0b7
2.0.0b8
2.0.0b9
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.1.1
2.1.2
2.1.3
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.14.1
2.14.2
2.14.3
2.14.4
2.14.5
2.14.6
2.15.0
2.15.1
2.15.2
2.15.3
2.15.4
2.2.0
2.3.1
2.3.2
2.4.0
2.5.0
2.5.1
2.5.2
2.5.3
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.8.0
2.9.0
2.9.1
Fixed in
2.15.5
References
Updated Jul 07, 2026 · Source: OSV.dev |
2.7.6
patch
Dependencies (41)
+ 33 more |
|
2.7.5
patch
1 CVE
CVE-2024-52524
PYSEC-2026-1403
GHSA-pjwm-cr36-mwv3
Jul 07, 2026
ReDoS in giskard's transformation.py (GHSL-2024-324)
Medium
Network
Low
None
None
ReDoS in Giskard text perturbation detectorA Remote Code Execution (ReDoS) vulnerability was discovered in Giskard component by the GitHub Security Lab team. When processing datasets with specific text patterns with Giskard detectors, this vulnerability could trigger exponential regex evaluation times, potentially leading to denial of service. DetailsThe vulnerability affects Giskard's punctuation removal transformation used in the text perturbation detection. A regex used to detect URLs and links was vulnerable to catastrophic backtracking that could be triggered by specific patterns in the text. Affected versionGiskard versions prior to 2.15.5 are affected. Users should upgrade to version 2.15.5 or later, which includes a fix for this vulnerability. ImpactThis vulnerability can cause extended computation times or crashes in Giskard when processing text containing certain patterns. CreditThis issue was discovered and reported by GHSL team member @kevinbackhouse (Kevin Backhouse). Affected versions
0.1.2
1.0.0
1.0.0a1
1.0.0a2
1.1.0
1.2.0
1.3.0
1.3.1
1.4.0
1.5.0
1.6.0
1.7.0
+ 92 more Show less
1.7.0a1
1.7.0a2
1.7.0a3
1.7.0a4
1.7.0a5
1.7.0a6
1.7.0a7
1.7.1
1.7.2
1.7.3
1.8.0
1.9.0
1.9.1
1.9.3
1.9.4
2.0.0
2.0.0b1
2.0.0b10
2.0.0b11
2.0.0b12
2.0.0b13
2.0.0b14
2.0.0b16
2.0.0b17
2.0.0b18
2.0.0b19
2.0.0b2
2.0.0b20
2.0.0b22
2.0.0b25
2.0.0b26
2.0.0b27
2.0.0b28
2.0.0b29
2.0.0b3
2.0.0b30
2.0.0b31
2.0.0b32
2.0.0b33
2.0.0b34
2.0.0b4
2.0.0b5
2.0.0b6
2.0.0b7
2.0.0b8
2.0.0b9
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.1.1
2.1.2
2.1.3
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.14.1
2.14.2
2.14.3
2.14.4
2.14.5
2.14.6
2.15.0
2.15.1
2.15.2
2.15.3
2.15.4
2.2.0
2.3.1
2.3.2
2.4.0
2.5.0
2.5.1
2.5.2
2.5.3
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.8.0
2.9.0
2.9.1
Fixed in
2.15.5
References
Updated Jul 07, 2026 · Source: OSV.dev |
2.7.5
patch
Dependencies (41)
+ 33 more |
|
2.7.4
patch
1 CVE
CVE-2024-52524
PYSEC-2026-1403
GHSA-pjwm-cr36-mwv3
Jul 07, 2026
ReDoS in giskard's transformation.py (GHSL-2024-324)
Medium
Network
Low
None
None
ReDoS in Giskard text perturbation detectorA Remote Code Execution (ReDoS) vulnerability was discovered in Giskard component by the GitHub Security Lab team. When processing datasets with specific text patterns with Giskard detectors, this vulnerability could trigger exponential regex evaluation times, potentially leading to denial of service. DetailsThe vulnerability affects Giskard's punctuation removal transformation used in the text perturbation detection. A regex used to detect URLs and links was vulnerable to catastrophic backtracking that could be triggered by specific patterns in the text. Affected versionGiskard versions prior to 2.15.5 are affected. Users should upgrade to version 2.15.5 or later, which includes a fix for this vulnerability. ImpactThis vulnerability can cause extended computation times or crashes in Giskard when processing text containing certain patterns. CreditThis issue was discovered and reported by GHSL team member @kevinbackhouse (Kevin Backhouse). Affected versions
0.1.2
1.0.0
1.0.0a1
1.0.0a2
1.1.0
1.2.0
1.3.0
1.3.1
1.4.0
1.5.0
1.6.0
1.7.0
+ 92 more Show less
1.7.0a1
1.7.0a2
1.7.0a3
1.7.0a4
1.7.0a5
1.7.0a6
1.7.0a7
1.7.1
1.7.2
1.7.3
1.8.0
1.9.0
1.9.1
1.9.3
1.9.4
2.0.0
2.0.0b1
2.0.0b10
2.0.0b11
2.0.0b12
2.0.0b13
2.0.0b14
2.0.0b16
2.0.0b17
2.0.0b18
2.0.0b19
2.0.0b2
2.0.0b20
2.0.0b22
2.0.0b25
2.0.0b26
2.0.0b27
2.0.0b28
2.0.0b29
2.0.0b3
2.0.0b30
2.0.0b31
2.0.0b32
2.0.0b33
2.0.0b34
2.0.0b4
2.0.0b5
2.0.0b6
2.0.0b7
2.0.0b8
2.0.0b9
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.1.1
2.1.2
2.1.3
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.14.1
2.14.2
2.14.3
2.14.4
2.14.5
2.14.6
2.15.0
2.15.1
2.15.2
2.15.3
2.15.4
2.2.0
2.3.1
2.3.2
2.4.0
2.5.0
2.5.1
2.5.2
2.5.3
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.8.0
2.9.0
2.9.1
Fixed in
2.15.5
References
Updated Jul 07, 2026 · Source: OSV.dev |
2.7.4
patch
Dependencies (40)
+ 32 more |
|
2.7.3
patch
1 CVE
CVE-2024-52524
PYSEC-2026-1403
GHSA-pjwm-cr36-mwv3
Jul 07, 2026
ReDoS in giskard's transformation.py (GHSL-2024-324)
Medium
Network
Low
None
None
ReDoS in Giskard text perturbation detectorA Remote Code Execution (ReDoS) vulnerability was discovered in Giskard component by the GitHub Security Lab team. When processing datasets with specific text patterns with Giskard detectors, this vulnerability could trigger exponential regex evaluation times, potentially leading to denial of service. DetailsThe vulnerability affects Giskard's punctuation removal transformation used in the text perturbation detection. A regex used to detect URLs and links was vulnerable to catastrophic backtracking that could be triggered by specific patterns in the text. Affected versionGiskard versions prior to 2.15.5 are affected. Users should upgrade to version 2.15.5 or later, which includes a fix for this vulnerability. ImpactThis vulnerability can cause extended computation times or crashes in Giskard when processing text containing certain patterns. CreditThis issue was discovered and reported by GHSL team member @kevinbackhouse (Kevin Backhouse). Affected versions
0.1.2
1.0.0
1.0.0a1
1.0.0a2
1.1.0
1.2.0
1.3.0
1.3.1
1.4.0
1.5.0
1.6.0
1.7.0
+ 92 more Show less
1.7.0a1
1.7.0a2
1.7.0a3
1.7.0a4
1.7.0a5
1.7.0a6
1.7.0a7
1.7.1
1.7.2
1.7.3
1.8.0
1.9.0
1.9.1
1.9.3
1.9.4
2.0.0
2.0.0b1
2.0.0b10
2.0.0b11
2.0.0b12
2.0.0b13
2.0.0b14
2.0.0b16
2.0.0b17
2.0.0b18
2.0.0b19
2.0.0b2
2.0.0b20
2.0.0b22
2.0.0b25
2.0.0b26
2.0.0b27
2.0.0b28
2.0.0b29
2.0.0b3
2.0.0b30
2.0.0b31
2.0.0b32
2.0.0b33
2.0.0b34
2.0.0b4
2.0.0b5
2.0.0b6
2.0.0b7
2.0.0b8
2.0.0b9
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.1.1
2.1.2
2.1.3
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.14.1
2.14.2
2.14.3
2.14.4
2.14.5
2.14.6
2.15.0
2.15.1
2.15.2
2.15.3
2.15.4
2.2.0
2.3.1
2.3.2
2.4.0
2.5.0
2.5.1
2.5.2
2.5.3
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.8.0
2.9.0
2.9.1
Fixed in
2.15.5
References
Updated Jul 07, 2026 · Source: OSV.dev |
2.7.3
patch
Dependencies (40)
+ 32 more |
|
2.7.2
patch
1 CVE
CVE-2024-52524
PYSEC-2026-1403
GHSA-pjwm-cr36-mwv3
Jul 07, 2026
ReDoS in giskard's transformation.py (GHSL-2024-324)
Medium
Network
Low
None
None
ReDoS in Giskard text perturbation detectorA Remote Code Execution (ReDoS) vulnerability was discovered in Giskard component by the GitHub Security Lab team. When processing datasets with specific text patterns with Giskard detectors, this vulnerability could trigger exponential regex evaluation times, potentially leading to denial of service. DetailsThe vulnerability affects Giskard's punctuation removal transformation used in the text perturbation detection. A regex used to detect URLs and links was vulnerable to catastrophic backtracking that could be triggered by specific patterns in the text. Affected versionGiskard versions prior to 2.15.5 are affected. Users should upgrade to version 2.15.5 or later, which includes a fix for this vulnerability. ImpactThis vulnerability can cause extended computation times or crashes in Giskard when processing text containing certain patterns. CreditThis issue was discovered and reported by GHSL team member @kevinbackhouse (Kevin Backhouse). Affected versions
0.1.2
1.0.0
1.0.0a1
1.0.0a2
1.1.0
1.2.0
1.3.0
1.3.1
1.4.0
1.5.0
1.6.0
1.7.0
+ 92 more Show less
1.7.0a1
1.7.0a2
1.7.0a3
1.7.0a4
1.7.0a5
1.7.0a6
1.7.0a7
1.7.1
1.7.2
1.7.3
1.8.0
1.9.0
1.9.1
1.9.3
1.9.4
2.0.0
2.0.0b1
2.0.0b10
2.0.0b11
2.0.0b12
2.0.0b13
2.0.0b14
2.0.0b16
2.0.0b17
2.0.0b18
2.0.0b19
2.0.0b2
2.0.0b20
2.0.0b22
2.0.0b25
2.0.0b26
2.0.0b27
2.0.0b28
2.0.0b29
2.0.0b3
2.0.0b30
2.0.0b31
2.0.0b32
2.0.0b33
2.0.0b34
2.0.0b4
2.0.0b5
2.0.0b6
2.0.0b7
2.0.0b8
2.0.0b9
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.1.1
2.1.2
2.1.3
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.14.1
2.14.2
2.14.3
2.14.4
2.14.5
2.14.6
2.15.0
2.15.1
2.15.2
2.15.3
2.15.4
2.2.0
2.3.1
2.3.2
2.4.0
2.5.0
2.5.1
2.5.2
2.5.3
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.8.0
2.9.0
2.9.1
Fixed in
2.15.5
References
Updated Jul 07, 2026 · Source: OSV.dev |
2.7.2
patch
Dependencies (40)
+ 32 more |
|
2.7.1
patch
1 CVE
CVE-2024-52524
PYSEC-2026-1403
GHSA-pjwm-cr36-mwv3
Jul 07, 2026
ReDoS in giskard's transformation.py (GHSL-2024-324)
Medium
Network
Low
None
None
ReDoS in Giskard text perturbation detectorA Remote Code Execution (ReDoS) vulnerability was discovered in Giskard component by the GitHub Security Lab team. When processing datasets with specific text patterns with Giskard detectors, this vulnerability could trigger exponential regex evaluation times, potentially leading to denial of service. DetailsThe vulnerability affects Giskard's punctuation removal transformation used in the text perturbation detection. A regex used to detect URLs and links was vulnerable to catastrophic backtracking that could be triggered by specific patterns in the text. Affected versionGiskard versions prior to 2.15.5 are affected. Users should upgrade to version 2.15.5 or later, which includes a fix for this vulnerability. ImpactThis vulnerability can cause extended computation times or crashes in Giskard when processing text containing certain patterns. CreditThis issue was discovered and reported by GHSL team member @kevinbackhouse (Kevin Backhouse). Affected versions
0.1.2
1.0.0
1.0.0a1
1.0.0a2
1.1.0
1.2.0
1.3.0
1.3.1
1.4.0
1.5.0
1.6.0
1.7.0
+ 92 more Show less
1.7.0a1
1.7.0a2
1.7.0a3
1.7.0a4
1.7.0a5
1.7.0a6
1.7.0a7
1.7.1
1.7.2
1.7.3
1.8.0
1.9.0
1.9.1
1.9.3
1.9.4
2.0.0
2.0.0b1
2.0.0b10
2.0.0b11
2.0.0b12
2.0.0b13
2.0.0b14
2.0.0b16
2.0.0b17
2.0.0b18
2.0.0b19
2.0.0b2
2.0.0b20
2.0.0b22
2.0.0b25
2.0.0b26
2.0.0b27
2.0.0b28
2.0.0b29
2.0.0b3
2.0.0b30
2.0.0b31
2.0.0b32
2.0.0b33
2.0.0b34
2.0.0b4
2.0.0b5
2.0.0b6
2.0.0b7
2.0.0b8
2.0.0b9
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.1.1
2.1.2
2.1.3
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.14.1
2.14.2
2.14.3
2.14.4
2.14.5
2.14.6
2.15.0
2.15.1
2.15.2
2.15.3
2.15.4
2.2.0
2.3.1
2.3.2
2.4.0
2.5.0
2.5.1
2.5.2
2.5.3
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.8.0
2.9.0
2.9.1
Fixed in
2.15.5
References
Updated Jul 07, 2026 · Source: OSV.dev |
2.7.1
patch
Dependencies (39)
+ 31 more |
|
2.7.0
minor
1 CVE
CVE-2024-52524
PYSEC-2026-1403
GHSA-pjwm-cr36-mwv3
Jul 07, 2026
ReDoS in giskard's transformation.py (GHSL-2024-324)
Medium
Network
Low
None
None
ReDoS in Giskard text perturbation detectorA Remote Code Execution (ReDoS) vulnerability was discovered in Giskard component by the GitHub Security Lab team. When processing datasets with specific text patterns with Giskard detectors, this vulnerability could trigger exponential regex evaluation times, potentially leading to denial of service. DetailsThe vulnerability affects Giskard's punctuation removal transformation used in the text perturbation detection. A regex used to detect URLs and links was vulnerable to catastrophic backtracking that could be triggered by specific patterns in the text. Affected versionGiskard versions prior to 2.15.5 are affected. Users should upgrade to version 2.15.5 or later, which includes a fix for this vulnerability. ImpactThis vulnerability can cause extended computation times or crashes in Giskard when processing text containing certain patterns. CreditThis issue was discovered and reported by GHSL team member @kevinbackhouse (Kevin Backhouse). Affected versions
0.1.2
1.0.0
1.0.0a1
1.0.0a2
1.1.0
1.2.0
1.3.0
1.3.1
1.4.0
1.5.0
1.6.0
1.7.0
+ 92 more Show less
1.7.0a1
1.7.0a2
1.7.0a3
1.7.0a4
1.7.0a5
1.7.0a6
1.7.0a7
1.7.1
1.7.2
1.7.3
1.8.0
1.9.0
1.9.1
1.9.3
1.9.4
2.0.0
2.0.0b1
2.0.0b10
2.0.0b11
2.0.0b12
2.0.0b13
2.0.0b14
2.0.0b16
2.0.0b17
2.0.0b18
2.0.0b19
2.0.0b2
2.0.0b20
2.0.0b22
2.0.0b25
2.0.0b26
2.0.0b27
2.0.0b28
2.0.0b29
2.0.0b3
2.0.0b30
2.0.0b31
2.0.0b32
2.0.0b33
2.0.0b34
2.0.0b4
2.0.0b5
2.0.0b6
2.0.0b7
2.0.0b8
2.0.0b9
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.1.1
2.1.2
2.1.3
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.14.1
2.14.2
2.14.3
2.14.4
2.14.5
2.14.6
2.15.0
2.15.1
2.15.2
2.15.3
2.15.4
2.2.0
2.3.1
2.3.2
2.4.0
2.5.0
2.5.1
2.5.2
2.5.3
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.8.0
2.9.0
2.9.1
Fixed in
2.15.5
References
Updated Jul 07, 2026 · Source: OSV.dev |
2.7.0
minor
Dependencies (38)
+ 30 more |
|
2.6.0
minor
1 CVE
CVE-2024-52524
PYSEC-2026-1403
GHSA-pjwm-cr36-mwv3
Jul 07, 2026
ReDoS in giskard's transformation.py (GHSL-2024-324)
Medium
Network
Low
None
None
ReDoS in Giskard text perturbation detectorA Remote Code Execution (ReDoS) vulnerability was discovered in Giskard component by the GitHub Security Lab team. When processing datasets with specific text patterns with Giskard detectors, this vulnerability could trigger exponential regex evaluation times, potentially leading to denial of service. DetailsThe vulnerability affects Giskard's punctuation removal transformation used in the text perturbation detection. A regex used to detect URLs and links was vulnerable to catastrophic backtracking that could be triggered by specific patterns in the text. Affected versionGiskard versions prior to 2.15.5 are affected. Users should upgrade to version 2.15.5 or later, which includes a fix for this vulnerability. ImpactThis vulnerability can cause extended computation times or crashes in Giskard when processing text containing certain patterns. CreditThis issue was discovered and reported by GHSL team member @kevinbackhouse (Kevin Backhouse). Affected versions
0.1.2
1.0.0
1.0.0a1
1.0.0a2
1.1.0
1.2.0
1.3.0
1.3.1
1.4.0
1.5.0
1.6.0
1.7.0
+ 92 more Show less
1.7.0a1
1.7.0a2
1.7.0a3
1.7.0a4
1.7.0a5
1.7.0a6
1.7.0a7
1.7.1
1.7.2
1.7.3
1.8.0
1.9.0
1.9.1
1.9.3
1.9.4
2.0.0
2.0.0b1
2.0.0b10
2.0.0b11
2.0.0b12
2.0.0b13
2.0.0b14
2.0.0b16
2.0.0b17
2.0.0b18
2.0.0b19
2.0.0b2
2.0.0b20
2.0.0b22
2.0.0b25
2.0.0b26
2.0.0b27
2.0.0b28
2.0.0b29
2.0.0b3
2.0.0b30
2.0.0b31
2.0.0b32
2.0.0b33
2.0.0b34
2.0.0b4
2.0.0b5
2.0.0b6
2.0.0b7
2.0.0b8
2.0.0b9
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.1.1
2.1.2
2.1.3
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.14.1
2.14.2
2.14.3
2.14.4
2.14.5
2.14.6
2.15.0
2.15.1
2.15.2
2.15.3
2.15.4
2.2.0
2.3.1
2.3.2
2.4.0
2.5.0
2.5.1
2.5.2
2.5.3
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.8.0
2.9.0
2.9.1
Fixed in
2.15.5
References
Updated Jul 07, 2026 · Source: OSV.dev |
2.6.0
minor
Dependencies (38)
+ 30 more |
|
2.5.3
patch
1 CVE
CVE-2024-52524
PYSEC-2026-1403
GHSA-pjwm-cr36-mwv3
Jul 07, 2026
ReDoS in giskard's transformation.py (GHSL-2024-324)
Medium
Network
Low
None
None
ReDoS in Giskard text perturbation detectorA Remote Code Execution (ReDoS) vulnerability was discovered in Giskard component by the GitHub Security Lab team. When processing datasets with specific text patterns with Giskard detectors, this vulnerability could trigger exponential regex evaluation times, potentially leading to denial of service. DetailsThe vulnerability affects Giskard's punctuation removal transformation used in the text perturbation detection. A regex used to detect URLs and links was vulnerable to catastrophic backtracking that could be triggered by specific patterns in the text. Affected versionGiskard versions prior to 2.15.5 are affected. Users should upgrade to version 2.15.5 or later, which includes a fix for this vulnerability. ImpactThis vulnerability can cause extended computation times or crashes in Giskard when processing text containing certain patterns. CreditThis issue was discovered and reported by GHSL team member @kevinbackhouse (Kevin Backhouse). Affected versions
0.1.2
1.0.0
1.0.0a1
1.0.0a2
1.1.0
1.2.0
1.3.0
1.3.1
1.4.0
1.5.0
1.6.0
1.7.0
+ 92 more Show less
1.7.0a1
1.7.0a2
1.7.0a3
1.7.0a4
1.7.0a5
1.7.0a6
1.7.0a7
1.7.1
1.7.2
1.7.3
1.8.0
1.9.0
1.9.1
1.9.3
1.9.4
2.0.0
2.0.0b1
2.0.0b10
2.0.0b11
2.0.0b12
2.0.0b13
2.0.0b14
2.0.0b16
2.0.0b17
2.0.0b18
2.0.0b19
2.0.0b2
2.0.0b20
2.0.0b22
2.0.0b25
2.0.0b26
2.0.0b27
2.0.0b28
2.0.0b29
2.0.0b3
2.0.0b30
2.0.0b31
2.0.0b32
2.0.0b33
2.0.0b34
2.0.0b4
2.0.0b5
2.0.0b6
2.0.0b7
2.0.0b8
2.0.0b9
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.1.1
2.1.2
2.1.3
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.14.1
2.14.2
2.14.3
2.14.4
2.14.5
2.14.6
2.15.0
2.15.1
2.15.2
2.15.3
2.15.4
2.2.0
2.3.1
2.3.2
2.4.0
2.5.0
2.5.1
2.5.2
2.5.3
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.8.0
2.9.0
2.9.1
Fixed in
2.15.5
References
Updated Jul 07, 2026 · Source: OSV.dev |
2.5.3
patch
Dependencies (38)
+ 30 more |
|
2.5.2
patch
1 CVE
CVE-2024-52524
PYSEC-2026-1403
GHSA-pjwm-cr36-mwv3
Jul 07, 2026
ReDoS in giskard's transformation.py (GHSL-2024-324)
Medium
Network
Low
None
None
ReDoS in Giskard text perturbation detectorA Remote Code Execution (ReDoS) vulnerability was discovered in Giskard component by the GitHub Security Lab team. When processing datasets with specific text patterns with Giskard detectors, this vulnerability could trigger exponential regex evaluation times, potentially leading to denial of service. DetailsThe vulnerability affects Giskard's punctuation removal transformation used in the text perturbation detection. A regex used to detect URLs and links was vulnerable to catastrophic backtracking that could be triggered by specific patterns in the text. Affected versionGiskard versions prior to 2.15.5 are affected. Users should upgrade to version 2.15.5 or later, which includes a fix for this vulnerability. ImpactThis vulnerability can cause extended computation times or crashes in Giskard when processing text containing certain patterns. CreditThis issue was discovered and reported by GHSL team member @kevinbackhouse (Kevin Backhouse). Affected versions
0.1.2
1.0.0
1.0.0a1
1.0.0a2
1.1.0
1.2.0
1.3.0
1.3.1
1.4.0
1.5.0
1.6.0
1.7.0
+ 92 more Show less
1.7.0a1
1.7.0a2
1.7.0a3
1.7.0a4
1.7.0a5
1.7.0a6
1.7.0a7
1.7.1
1.7.2
1.7.3
1.8.0
1.9.0
1.9.1
1.9.3
1.9.4
2.0.0
2.0.0b1
2.0.0b10
2.0.0b11
2.0.0b12
2.0.0b13
2.0.0b14
2.0.0b16
2.0.0b17
2.0.0b18
2.0.0b19
2.0.0b2
2.0.0b20
2.0.0b22
2.0.0b25
2.0.0b26
2.0.0b27
2.0.0b28
2.0.0b29
2.0.0b3
2.0.0b30
2.0.0b31
2.0.0b32
2.0.0b33
2.0.0b34
2.0.0b4
2.0.0b5
2.0.0b6
2.0.0b7
2.0.0b8
2.0.0b9
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.1.1
2.1.2
2.1.3
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.14.1
2.14.2
2.14.3
2.14.4
2.14.5
2.14.6
2.15.0
2.15.1
2.15.2
2.15.3
2.15.4
2.2.0
2.3.1
2.3.2
2.4.0
2.5.0
2.5.1
2.5.2
2.5.3
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.8.0
2.9.0
2.9.1
Fixed in
2.15.5
References
Updated Jul 07, 2026 · Source: OSV.dev |
2.5.2
patch
Dependencies (38)
+ 30 more |
|
2.5.1
patch
1 CVE
CVE-2024-52524
PYSEC-2026-1403
GHSA-pjwm-cr36-mwv3
Jul 07, 2026
ReDoS in giskard's transformation.py (GHSL-2024-324)
Medium
Network
Low
None
None
ReDoS in Giskard text perturbation detectorA Remote Code Execution (ReDoS) vulnerability was discovered in Giskard component by the GitHub Security Lab team. When processing datasets with specific text patterns with Giskard detectors, this vulnerability could trigger exponential regex evaluation times, potentially leading to denial of service. DetailsThe vulnerability affects Giskard's punctuation removal transformation used in the text perturbation detection. A regex used to detect URLs and links was vulnerable to catastrophic backtracking that could be triggered by specific patterns in the text. Affected versionGiskard versions prior to 2.15.5 are affected. Users should upgrade to version 2.15.5 or later, which includes a fix for this vulnerability. ImpactThis vulnerability can cause extended computation times or crashes in Giskard when processing text containing certain patterns. CreditThis issue was discovered and reported by GHSL team member @kevinbackhouse (Kevin Backhouse). Affected versions
0.1.2
1.0.0
1.0.0a1
1.0.0a2
1.1.0
1.2.0
1.3.0
1.3.1
1.4.0
1.5.0
1.6.0
1.7.0
+ 92 more Show less
1.7.0a1
1.7.0a2
1.7.0a3
1.7.0a4
1.7.0a5
1.7.0a6
1.7.0a7
1.7.1
1.7.2
1.7.3
1.8.0
1.9.0
1.9.1
1.9.3
1.9.4
2.0.0
2.0.0b1
2.0.0b10
2.0.0b11
2.0.0b12
2.0.0b13
2.0.0b14
2.0.0b16
2.0.0b17
2.0.0b18
2.0.0b19
2.0.0b2
2.0.0b20
2.0.0b22
2.0.0b25
2.0.0b26
2.0.0b27
2.0.0b28
2.0.0b29
2.0.0b3
2.0.0b30
2.0.0b31
2.0.0b32
2.0.0b33
2.0.0b34
2.0.0b4
2.0.0b5
2.0.0b6
2.0.0b7
2.0.0b8
2.0.0b9
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.1.1
2.1.2
2.1.3
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.14.1
2.14.2
2.14.3
2.14.4
2.14.5
2.14.6
2.15.0
2.15.1
2.15.2
2.15.3
2.15.4
2.2.0
2.3.1
2.3.2
2.4.0
2.5.0
2.5.1
2.5.2
2.5.3
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.8.0
2.9.0
2.9.1
Fixed in
2.15.5
References
Updated Jul 07, 2026 · Source: OSV.dev |
2.5.1
patch
Dependencies (38)
+ 30 more |
|
2.5.0
minor
1 CVE
CVE-2024-52524
PYSEC-2026-1403
GHSA-pjwm-cr36-mwv3
Jul 07, 2026
ReDoS in giskard's transformation.py (GHSL-2024-324)
Medium
Network
Low
None
None
ReDoS in Giskard text perturbation detectorA Remote Code Execution (ReDoS) vulnerability was discovered in Giskard component by the GitHub Security Lab team. When processing datasets with specific text patterns with Giskard detectors, this vulnerability could trigger exponential regex evaluation times, potentially leading to denial of service. DetailsThe vulnerability affects Giskard's punctuation removal transformation used in the text perturbation detection. A regex used to detect URLs and links was vulnerable to catastrophic backtracking that could be triggered by specific patterns in the text. Affected versionGiskard versions prior to 2.15.5 are affected. Users should upgrade to version 2.15.5 or later, which includes a fix for this vulnerability. ImpactThis vulnerability can cause extended computation times or crashes in Giskard when processing text containing certain patterns. CreditThis issue was discovered and reported by GHSL team member @kevinbackhouse (Kevin Backhouse). Affected versions
0.1.2
1.0.0
1.0.0a1
1.0.0a2
1.1.0
1.2.0
1.3.0
1.3.1
1.4.0
1.5.0
1.6.0
1.7.0
+ 92 more Show less
1.7.0a1
1.7.0a2
1.7.0a3
1.7.0a4
1.7.0a5
1.7.0a6
1.7.0a7
1.7.1
1.7.2
1.7.3
1.8.0
1.9.0
1.9.1
1.9.3
1.9.4
2.0.0
2.0.0b1
2.0.0b10
2.0.0b11
2.0.0b12
2.0.0b13
2.0.0b14
2.0.0b16
2.0.0b17
2.0.0b18
2.0.0b19
2.0.0b2
2.0.0b20
2.0.0b22
2.0.0b25
2.0.0b26
2.0.0b27
2.0.0b28
2.0.0b29
2.0.0b3
2.0.0b30
2.0.0b31
2.0.0b32
2.0.0b33
2.0.0b34
2.0.0b4
2.0.0b5
2.0.0b6
2.0.0b7
2.0.0b8
2.0.0b9
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.1.1
2.1.2
2.1.3
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.14.1
2.14.2
2.14.3
2.14.4
2.14.5
2.14.6
2.15.0
2.15.1
2.15.2
2.15.3
2.15.4
2.2.0
2.3.1
2.3.2
2.4.0
2.5.0
2.5.1
2.5.2
2.5.3
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.8.0
2.9.0
2.9.1
Fixed in
2.15.5
References
Updated Jul 07, 2026 · Source: OSV.dev |
2.5.0
minor
Dependencies (38)
+ 30 more |
|
2.4.0
minor
1 CVE
CVE-2024-52524
PYSEC-2026-1403
GHSA-pjwm-cr36-mwv3
Jul 07, 2026
ReDoS in giskard's transformation.py (GHSL-2024-324)
Medium
Network
Low
None
None
ReDoS in Giskard text perturbation detectorA Remote Code Execution (ReDoS) vulnerability was discovered in Giskard component by the GitHub Security Lab team. When processing datasets with specific text patterns with Giskard detectors, this vulnerability could trigger exponential regex evaluation times, potentially leading to denial of service. DetailsThe vulnerability affects Giskard's punctuation removal transformation used in the text perturbation detection. A regex used to detect URLs and links was vulnerable to catastrophic backtracking that could be triggered by specific patterns in the text. Affected versionGiskard versions prior to 2.15.5 are affected. Users should upgrade to version 2.15.5 or later, which includes a fix for this vulnerability. ImpactThis vulnerability can cause extended computation times or crashes in Giskard when processing text containing certain patterns. CreditThis issue was discovered and reported by GHSL team member @kevinbackhouse (Kevin Backhouse). Affected versions
0.1.2
1.0.0
1.0.0a1
1.0.0a2
1.1.0
1.2.0
1.3.0
1.3.1
1.4.0
1.5.0
1.6.0
1.7.0
+ 92 more Show less
1.7.0a1
1.7.0a2
1.7.0a3
1.7.0a4
1.7.0a5
1.7.0a6
1.7.0a7
1.7.1
1.7.2
1.7.3
1.8.0
1.9.0
1.9.1
1.9.3
1.9.4
2.0.0
2.0.0b1
2.0.0b10
2.0.0b11
2.0.0b12
2.0.0b13
2.0.0b14
2.0.0b16
2.0.0b17
2.0.0b18
2.0.0b19
2.0.0b2
2.0.0b20
2.0.0b22
2.0.0b25
2.0.0b26
2.0.0b27
2.0.0b28
2.0.0b29
2.0.0b3
2.0.0b30
2.0.0b31
2.0.0b32
2.0.0b33
2.0.0b34
2.0.0b4
2.0.0b5
2.0.0b6
2.0.0b7
2.0.0b8
2.0.0b9
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.1.1
2.1.2
2.1.3
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.14.1
2.14.2
2.14.3
2.14.4
2.14.5
2.14.6
2.15.0
2.15.1
2.15.2
2.15.3
2.15.4
2.2.0
2.3.1
2.3.2
2.4.0
2.5.0
2.5.1
2.5.2
2.5.3
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.8.0
2.9.0
2.9.1
Fixed in
2.15.5
References
Updated Jul 07, 2026 · Source: OSV.dev |
2.4.0
minor
Dependencies (38)
+ 30 more |
|
2.3.2
patch
1 CVE
CVE-2024-52524
PYSEC-2026-1403
GHSA-pjwm-cr36-mwv3
Jul 07, 2026
ReDoS in giskard's transformation.py (GHSL-2024-324)
Medium
Network
Low
None
None
ReDoS in Giskard text perturbation detectorA Remote Code Execution (ReDoS) vulnerability was discovered in Giskard component by the GitHub Security Lab team. When processing datasets with specific text patterns with Giskard detectors, this vulnerability could trigger exponential regex evaluation times, potentially leading to denial of service. DetailsThe vulnerability affects Giskard's punctuation removal transformation used in the text perturbation detection. A regex used to detect URLs and links was vulnerable to catastrophic backtracking that could be triggered by specific patterns in the text. Affected versionGiskard versions prior to 2.15.5 are affected. Users should upgrade to version 2.15.5 or later, which includes a fix for this vulnerability. ImpactThis vulnerability can cause extended computation times or crashes in Giskard when processing text containing certain patterns. CreditThis issue was discovered and reported by GHSL team member @kevinbackhouse (Kevin Backhouse). Affected versions
0.1.2
1.0.0
1.0.0a1
1.0.0a2
1.1.0
1.2.0
1.3.0
1.3.1
1.4.0
1.5.0
1.6.0
1.7.0
+ 92 more Show less
1.7.0a1
1.7.0a2
1.7.0a3
1.7.0a4
1.7.0a5
1.7.0a6
1.7.0a7
1.7.1
1.7.2
1.7.3
1.8.0
1.9.0
1.9.1
1.9.3
1.9.4
2.0.0
2.0.0b1
2.0.0b10
2.0.0b11
2.0.0b12
2.0.0b13
2.0.0b14
2.0.0b16
2.0.0b17
2.0.0b18
2.0.0b19
2.0.0b2
2.0.0b20
2.0.0b22
2.0.0b25
2.0.0b26
2.0.0b27
2.0.0b28
2.0.0b29
2.0.0b3
2.0.0b30
2.0.0b31
2.0.0b32
2.0.0b33
2.0.0b34
2.0.0b4
2.0.0b5
2.0.0b6
2.0.0b7
2.0.0b8
2.0.0b9
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.1.1
2.1.2
2.1.3
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.14.1
2.14.2
2.14.3
2.14.4
2.14.5
2.14.6
2.15.0
2.15.1
2.15.2
2.15.3
2.15.4
2.2.0
2.3.1
2.3.2
2.4.0
2.5.0
2.5.1
2.5.2
2.5.3
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.8.0
2.9.0
2.9.1
Fixed in
2.15.5
References
Updated Jul 07, 2026 · Source: OSV.dev |
2.3.2
patch
Dependencies (38)
+ 30 more |
|
2.3.1
minor
1 CVE
CVE-2024-52524
PYSEC-2026-1403
GHSA-pjwm-cr36-mwv3
Jul 07, 2026
ReDoS in giskard's transformation.py (GHSL-2024-324)
Medium
Network
Low
None
None
ReDoS in Giskard text perturbation detectorA Remote Code Execution (ReDoS) vulnerability was discovered in Giskard component by the GitHub Security Lab team. When processing datasets with specific text patterns with Giskard detectors, this vulnerability could trigger exponential regex evaluation times, potentially leading to denial of service. DetailsThe vulnerability affects Giskard's punctuation removal transformation used in the text perturbation detection. A regex used to detect URLs and links was vulnerable to catastrophic backtracking that could be triggered by specific patterns in the text. Affected versionGiskard versions prior to 2.15.5 are affected. Users should upgrade to version 2.15.5 or later, which includes a fix for this vulnerability. ImpactThis vulnerability can cause extended computation times or crashes in Giskard when processing text containing certain patterns. CreditThis issue was discovered and reported by GHSL team member @kevinbackhouse (Kevin Backhouse). Affected versions
0.1.2
1.0.0
1.0.0a1
1.0.0a2
1.1.0
1.2.0
1.3.0
1.3.1
1.4.0
1.5.0
1.6.0
1.7.0
+ 92 more Show less
1.7.0a1
1.7.0a2
1.7.0a3
1.7.0a4
1.7.0a5
1.7.0a6
1.7.0a7
1.7.1
1.7.2
1.7.3
1.8.0
1.9.0
1.9.1
1.9.3
1.9.4
2.0.0
2.0.0b1
2.0.0b10
2.0.0b11
2.0.0b12
2.0.0b13
2.0.0b14
2.0.0b16
2.0.0b17
2.0.0b18
2.0.0b19
2.0.0b2
2.0.0b20
2.0.0b22
2.0.0b25
2.0.0b26
2.0.0b27
2.0.0b28
2.0.0b29
2.0.0b3
2.0.0b30
2.0.0b31
2.0.0b32
2.0.0b33
2.0.0b34
2.0.0b4
2.0.0b5
2.0.0b6
2.0.0b7
2.0.0b8
2.0.0b9
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.1.1
2.1.2
2.1.3
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.14.1
2.14.2
2.14.3
2.14.4
2.14.5
2.14.6
2.15.0
2.15.1
2.15.2
2.15.3
2.15.4
2.2.0
2.3.1
2.3.2
2.4.0
2.5.0
2.5.1
2.5.2
2.5.3
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.8.0
2.9.0
2.9.1
Fixed in
2.15.5
References
Updated Jul 07, 2026 · Source: OSV.dev |
2.3.1
minor
Dependencies (38)
+ 30 more |
|
2.2.0
minor
1 CVE
CVE-2024-52524
PYSEC-2026-1403
GHSA-pjwm-cr36-mwv3
Jul 07, 2026
ReDoS in giskard's transformation.py (GHSL-2024-324)
Medium
Network
Low
None
None
ReDoS in Giskard text perturbation detectorA Remote Code Execution (ReDoS) vulnerability was discovered in Giskard component by the GitHub Security Lab team. When processing datasets with specific text patterns with Giskard detectors, this vulnerability could trigger exponential regex evaluation times, potentially leading to denial of service. DetailsThe vulnerability affects Giskard's punctuation removal transformation used in the text perturbation detection. A regex used to detect URLs and links was vulnerable to catastrophic backtracking that could be triggered by specific patterns in the text. Affected versionGiskard versions prior to 2.15.5 are affected. Users should upgrade to version 2.15.5 or later, which includes a fix for this vulnerability. ImpactThis vulnerability can cause extended computation times or crashes in Giskard when processing text containing certain patterns. CreditThis issue was discovered and reported by GHSL team member @kevinbackhouse (Kevin Backhouse). Affected versions
0.1.2
1.0.0
1.0.0a1
1.0.0a2
1.1.0
1.2.0
1.3.0
1.3.1
1.4.0
1.5.0
1.6.0
1.7.0
+ 92 more Show less
1.7.0a1
1.7.0a2
1.7.0a3
1.7.0a4
1.7.0a5
1.7.0a6
1.7.0a7
1.7.1
1.7.2
1.7.3
1.8.0
1.9.0
1.9.1
1.9.3
1.9.4
2.0.0
2.0.0b1
2.0.0b10
2.0.0b11
2.0.0b12
2.0.0b13
2.0.0b14
2.0.0b16
2.0.0b17
2.0.0b18
2.0.0b19
2.0.0b2
2.0.0b20
2.0.0b22
2.0.0b25
2.0.0b26
2.0.0b27
2.0.0b28
2.0.0b29
2.0.0b3
2.0.0b30
2.0.0b31
2.0.0b32
2.0.0b33
2.0.0b34
2.0.0b4
2.0.0b5
2.0.0b6
2.0.0b7
2.0.0b8
2.0.0b9
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.1.1
2.1.2
2.1.3
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.14.1
2.14.2
2.14.3
2.14.4
2.14.5
2.14.6
2.15.0
2.15.1
2.15.2
2.15.3
2.15.4
2.2.0
2.3.1
2.3.2
2.4.0
2.5.0
2.5.1
2.5.2
2.5.3
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.8.0
2.9.0
2.9.1
Fixed in
2.15.5
References
Updated Jul 07, 2026 · Source: OSV.dev |
2.2.0
minor
Dependencies (38)
+ 30 more |
|
2.1.3
patch
1 CVE
CVE-2024-52524
PYSEC-2026-1403
GHSA-pjwm-cr36-mwv3
Jul 07, 2026
ReDoS in giskard's transformation.py (GHSL-2024-324)
Medium
Network
Low
None
None
ReDoS in Giskard text perturbation detectorA Remote Code Execution (ReDoS) vulnerability was discovered in Giskard component by the GitHub Security Lab team. When processing datasets with specific text patterns with Giskard detectors, this vulnerability could trigger exponential regex evaluation times, potentially leading to denial of service. DetailsThe vulnerability affects Giskard's punctuation removal transformation used in the text perturbation detection. A regex used to detect URLs and links was vulnerable to catastrophic backtracking that could be triggered by specific patterns in the text. Affected versionGiskard versions prior to 2.15.5 are affected. Users should upgrade to version 2.15.5 or later, which includes a fix for this vulnerability. ImpactThis vulnerability can cause extended computation times or crashes in Giskard when processing text containing certain patterns. CreditThis issue was discovered and reported by GHSL team member @kevinbackhouse (Kevin Backhouse). Affected versions
0.1.2
1.0.0
1.0.0a1
1.0.0a2
1.1.0
1.2.0
1.3.0
1.3.1
1.4.0
1.5.0
1.6.0
1.7.0
+ 92 more Show less
1.7.0a1
1.7.0a2
1.7.0a3
1.7.0a4
1.7.0a5
1.7.0a6
1.7.0a7
1.7.1
1.7.2
1.7.3
1.8.0
1.9.0
1.9.1
1.9.3
1.9.4
2.0.0
2.0.0b1
2.0.0b10
2.0.0b11
2.0.0b12
2.0.0b13
2.0.0b14
2.0.0b16
2.0.0b17
2.0.0b18
2.0.0b19
2.0.0b2
2.0.0b20
2.0.0b22
2.0.0b25
2.0.0b26
2.0.0b27
2.0.0b28
2.0.0b29
2.0.0b3
2.0.0b30
2.0.0b31
2.0.0b32
2.0.0b33
2.0.0b34
2.0.0b4
2.0.0b5
2.0.0b6
2.0.0b7
2.0.0b8
2.0.0b9
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.1.1
2.1.2
2.1.3
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.14.1
2.14.2
2.14.3
2.14.4
2.14.5
2.14.6
2.15.0
2.15.1
2.15.2
2.15.3
2.15.4
2.2.0
2.3.1
2.3.2
2.4.0
2.5.0
2.5.1
2.5.2
2.5.3
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.8.0
2.9.0
2.9.1
Fixed in
2.15.5
References
Updated Jul 07, 2026 · Source: OSV.dev |
2.1.3
patch
Dependencies (38)
+ 30 more |
|
2.1.2
patch
1 CVE
CVE-2024-52524
PYSEC-2026-1403
GHSA-pjwm-cr36-mwv3
Jul 07, 2026
ReDoS in giskard's transformation.py (GHSL-2024-324)
Medium
Network
Low
None
None
ReDoS in Giskard text perturbation detectorA Remote Code Execution (ReDoS) vulnerability was discovered in Giskard component by the GitHub Security Lab team. When processing datasets with specific text patterns with Giskard detectors, this vulnerability could trigger exponential regex evaluation times, potentially leading to denial of service. DetailsThe vulnerability affects Giskard's punctuation removal transformation used in the text perturbation detection. A regex used to detect URLs and links was vulnerable to catastrophic backtracking that could be triggered by specific patterns in the text. Affected versionGiskard versions prior to 2.15.5 are affected. Users should upgrade to version 2.15.5 or later, which includes a fix for this vulnerability. ImpactThis vulnerability can cause extended computation times or crashes in Giskard when processing text containing certain patterns. CreditThis issue was discovered and reported by GHSL team member @kevinbackhouse (Kevin Backhouse). Affected versions
0.1.2
1.0.0
1.0.0a1
1.0.0a2
1.1.0
1.2.0
1.3.0
1.3.1
1.4.0
1.5.0
1.6.0
1.7.0
+ 92 more Show less
1.7.0a1
1.7.0a2
1.7.0a3
1.7.0a4
1.7.0a5
1.7.0a6
1.7.0a7
1.7.1
1.7.2
1.7.3
1.8.0
1.9.0
1.9.1
1.9.3
1.9.4
2.0.0
2.0.0b1
2.0.0b10
2.0.0b11
2.0.0b12
2.0.0b13
2.0.0b14
2.0.0b16
2.0.0b17
2.0.0b18
2.0.0b19
2.0.0b2
2.0.0b20
2.0.0b22
2.0.0b25
2.0.0b26
2.0.0b27
2.0.0b28
2.0.0b29
2.0.0b3
2.0.0b30
2.0.0b31
2.0.0b32
2.0.0b33
2.0.0b34
2.0.0b4
2.0.0b5
2.0.0b6
2.0.0b7
2.0.0b8
2.0.0b9
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.1.1
2.1.2
2.1.3
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.14.1
2.14.2
2.14.3
2.14.4
2.14.5
2.14.6
2.15.0
2.15.1
2.15.2
2.15.3
2.15.4
2.2.0
2.3.1
2.3.2
2.4.0
2.5.0
2.5.1
2.5.2
2.5.3
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.8.0
2.9.0
2.9.1
Fixed in
2.15.5
References
Updated Jul 07, 2026 · Source: OSV.dev |
2.1.2
patch
Dependencies (38)
+ 30 more |