PYSEC-2026-1403
ReDoS in giskard's transformation.py (GHSL-2024-324)
Quick fix
PYSEC-2026-1403 — giskard: upgrade to the fixed version with the command below.
pip install --upgrade 'giskard>=2.15.5'Details
# ReDoS in Giskard text perturbation detector
A Remote Code Execution (ReDoS) vulnerability was discovered in Giskard component by the [GitHub Security Lab](https://securitylab.github.com) team. When processing datasets with specific text patterns with Giskard detectors, this vulnerability could trigger exponential regex evaluation times, potentially leading to denial of service.
## Details
The vulnerability affects Giskard's punctuation removal transformation used in the text perturbation detection. A regex used to detect URLs and links was vulnerable to catastrophic backtracking that could be triggered by specific patterns in the text.
## Affected version
Giskard versions prior to 2.15.5 are affected. Users should upgrade to version 2.15.5 or later, which includes a fix for this vulnerability.
## Impact
This vulnerability can cause extended computation times or crashes in Giskard when processing text containing certain patterns.
## Credit
This issue was discovered and reported by GHSL team member [@kevinbackhouse (Kevin Backhouse)](https://github.com/kevinbackhouse).
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/Giskard-AI/giskard/security/advisories/GHSA-pjwm-cr36-mwv3[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2024-52524[ADVISORY]
- https://github.com/Giskard-AI/giskard/commit/48ce81f5c626171767188d6f0669498fb613b4d3[WEB]
- https://github.com/Giskard-AI/giskard[PACKAGE]
- https://pypi.org/project/giskard[PACKAGE]
- https://github.com/advisories/GHSA-pjwm-cr36-mwv3[ADVISORY]