OVERVIEW: CVE-2026-40319 affects Giskard, an open-source testing framework for AI models, in versions prior to 1.0.2b1. The vulnerability exists in the RegexMatching check component, which fails to implement safeguards when processing user-supplied regular expression patterns, allowing malicious regex patterns to trigger catastrophic backtracking and cause denial of service. SEVERITY: The attack requires write access to check definitions, indicating a moderate barrier to exploitation that limits the threat to authenticated or insider actors. The crafted regex pattern causes the process to hang indefinitely, resulting in application-level denial of service. The FAUCET Risk Score of 22.0/100 and exceptionally low EPSS score of 0.00007 suggest this is a low-risk vulnerability in practical terms, likely due to the access requirements and limited attack surface. EXPLOITATION STATUS: There is no indication of active exploitation, as evidenced by the vulnerability's absence from the Known Exploited Vulnerabilities (KEV) catalog and its inactive status on threat hot lists. The vulnerability has been patched in giskard-checks version 1.0.2b1, and community attention appears minimal given the low EPSS and risk scores.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.0.2CPE matchmatch criteria | cpe:2.3:a:giskard:giskard:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.