{"id":"PYSEC-2026-1403","summary":"ReDoS in giskard's transformation.py (GHSL-2024-324)","details":"# ReDoS in Giskard text perturbation detector\n\nA Remote Code Execution (ReDoS) vulnerability was discovered in Giskard component by the [GitHub Security Lab](https://securitylab.github.com) team. When processing datasets with specific text patterns with Giskard detectors, this vulnerability could trigger exponential regex evaluation times, potentially leading to denial of service.\n\n## Details\n\nThe vulnerability affects Giskard's punctuation removal transformation used in the text perturbation detection. A regex used to detect URLs and links was vulnerable to catastrophic backtracking that could be triggered by specific patterns in the text.\n\n## Affected version\n\nGiskard versions prior to 2.15.5 are affected. Users should upgrade to version 2.15.5 or later, which includes a fix for this vulnerability.\n\n## Impact\n\nThis vulnerability can cause extended computation times or crashes in Giskard when processing text containing certain patterns.\n\n## Credit\n\nThis issue was discovered and reported by GHSL team member [@kevinbackhouse (Kevin Backhouse)](https://github.com/kevinbackhouse).","aliases":["CVE-2024-52524","GHSA-pjwm-cr36-mwv3"],"modified":"2026-07-07T17:46:43.215296411Z","published":"2026-07-07T14:34:44.521463Z","references":[{"type":"WEB","url":"https://github.com/Giskard-AI/giskard/security/advisories/GHSA-pjwm-cr36-mwv3"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-52524"},{"type":"WEB","url":"https://github.com/Giskard-AI/giskard/commit/48ce81f5c626171767188d6f0669498fb613b4d3"},{"type":"PACKAGE","url":"https://github.com/Giskard-AI/giskard"},{"type":"PACKAGE","url":"https://pypi.org/project/giskard"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-pjwm-cr36-mwv3"}],"affected":[{"package":{"name":"giskard","ecosystem":"PyPI","purl":"pkg:pypi/giskard"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.15.5"}]}],"versions":["0.1.2","1.0.0","1.0.0a1","1.0.0a2","1.1.0","1.2.0","1.3.0","1.3.1","1.4.0","1.5.0","1.6.0","1.7.0","1.7.0a1","1.7.0a2","1.7.0a3","1.7.0a4","1.7.0a5","1.7.0a6","1.7.0a7","1.7.1","1.7.2","1.7.3","1.8.0","1.9.0","1.9.1","1.9.3","1.9.4","2.0.0","2.0.0b1","2.0.0b10","2.0.0b11","2.0.0b12","2.0.0b13","2.0.0b14","2.0.0b16","2.0.0b17","2.0.0b18","2.0.0b19","2.0.0b2","2.0.0b20","2.0.0b22","2.0.0b25","2.0.0b26","2.0.0b27","2.0.0b28","2.0.0b29","2.0.0b3","2.0.0b30","2.0.0b31","2.0.0b32","2.0.0b33","2.0.0b34","2.0.0b4","2.0.0b5","2.0.0b6","2.0.0b7","2.0.0b8","2.0.0b9","2.0.1","2.0.2","2.0.3","2.0.4","2.0.5","2.0.6","2.0.7","2.1.1","2.1.2","2.1.3","2.10.0","2.11.0","2.12.0","2.13.0","2.14.0","2.14.1","2.14.2","2.14.3","2.14.4","2.14.5","2.14.6","2.15.0","2.15.1","2.15.2","2.15.3","2.15.4","2.2.0","2.3.1","2.3.2","2.4.0","2.5.0","2.5.1","2.5.2","2.5.3","2.6.0","2.7.0","2.7.1","2.7.2","2.7.3","2.7.4","2.7.5","2.7.6","2.7.7","2.8.0","2.9.0","2.9.1"],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/giskard/PYSEC-2026-1403.yaml"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Clear"}]}