Vulnerability Details CVE-2026-40319
Giskard is an open-source testing framework for AI models. In versions prior to 1.0.2b1, the RegexMatching check passes a user-supplied regular expression pattern directly to Python's re.search() without any timeout or complexity guard. A crafted regex pattern can trigger catastrophic backtracking, causing the process to hang indefinitely. Exploitation requires write access to a check definition and subsequent execution of the test suite. This issue has been fixed in giskard-checks version 1.0.2b1.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 0.5%
CVSS Severity
CVSS v3 Score 5.5
Products affected by CVE-2026-40319
-
cpe:2.3:a:giskard:giskard:0.1.1
-
cpe:2.3:a:giskard:giskard:0.2.0
-
cpe:2.3:a:giskard:giskard:1.0.0