THREAT OPS › Threat News › [GHSA] GHSA-j535-v25q-vx3q (high) — n8n: Regular Expression Denial of Service in the Default Blocked-File-Pattern Match via a Git Node Clone Path
[GHSA] GHSA-j535-v25q-vx3q (high) — n8n: Regular Expression Denial of Service in the Default Blocked-File-Pattern Match via a Git Node Clone Path
GHSA-j535-v25q-vx3q Severity: high CVE: CVE-2026-86081
n8n: Regular Expression Denial of Service in the Default Blocked-File-Pattern Match via a Git Node Clone Path
## Impact
The Git node's clone operation matched the destination path against the default `N8N_BLOCK_FILE_PATTERNS` expression, which was written so that a crafted path caused catastrophic backtracking. Evaluation runs synchronously
Indicators of compromise
- CVE-2026-86081cve
Original source: https://github.com/advisories/GHSA-j535-v25q-vx3q