Dulwich
This hub aggregates every CVE we track for Dulwich, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
7
CVEs tracked
1
Critical
4
High
0
In CISA KEV
Severity distribution
HIGH4LOW1MEDIUM1CRITICAL1
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
4
0
2024-082026-07
Latest CVEs
The 7 most recently published vulnerabilities affecting Dulwich.
- CVE-2026-52726Dulwich's submodule path traversal in porcelain.submodule_update / porcelain.clone(recurse_submodules=True) yields RCE via attacker-dropped .git/hooks payload7.5
- CVE-2026-47734Dulwich has unbounded memory allocation in receive-pack from crafted thin packs5.7
- CVE-2026-47712Dulwich doesn't sanitize commit subjects in `porcelain.format_patch`3.3
- CVE-2026-42305Dulwich has an arbitrary file write via NTFS-hostile tree entries on Windows8.8
- CVE-2017-16228Dulwich before 0.18.5, when an SSH subprocess is used, allows remote attackers to execute arbitrary commands via an ssh URL with an initial dash character in the hostname, a related issue to CVE-20...9.8
- CVE-2015-0838Buffer overflow in the C implementation of the apply_delta function in _pack.c in Dulwich before 0.9.9 allows remote attackers to execute arbitrary code via a crafted pack file.7.5
- CVE-2014-9706The build_index_from_tree function in index.py in Dulwich before 0.9.9 allows remote attackers to execute arbitrary code via a commit with a directory path starting with .git/, which is not properl...7.5
Product normalization is registry-driven with AI assist and human review. How it works