dulwich
PyPI7 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting dulwichpage 1 of 1
- CVE-2014-9706NONECVSS 0.0EG 0.0✓ Fixed in 0.9.92015-03-31
vulnerable: 0.0.1 ... 0.9.8 (33 versions)
The build_index_from_tree function in index.py in Dulwich before 0.9.9 allows remote attackers to execute arbitrary code via a commit with a directory path starting with .git/, which is not properly handled when checking out a working tree.
- CVE-2015-0838NONECVSS 0.0EG 0.0✓ Fixed in 0.9.92015-03-31
vulnerable: 0.0.1 ... 0.9.8 (33 versions)
Buffer overflow in the C implementation of the apply_delta function in _pack.c in Dulwich before 0.9.9 allows remote attackers to execute arbitrary code via a crafted pack file.
- CVE-2017-16228CRITICALCVSS 9.8EG 9.8✓ Fixed in 0.18.52017-10-29
vulnerable: 0.0.1 ... 0.9.9 (56 versions)
Dulwich before 0.18.5, when an SSH subprocess is used, allows remote attackers to execute arbitrary commands via an ssh URL with an initial dash character in the hostname, a related issue to CVE-2017-9800, CVE-2017-12836, CVE-2017-12976, C…
- CVE-2026-42305HIGHCVSS 8.8EG 8.8✓ Fixed in 1.2.52026-05-28
vulnerable: 0.10.0 ... 1.2.4 (133 versions)
Dulwich is a pure-Python implementation of the Git file formats and protocols. Versions starting with 0.10.0 and prior to 1.2.5 have an arbitrary file write leading to remote code execution when cloning or checking out a malicious Git repo…
- CVE-2026-42563HIGHCVSS 7.7EG 7.7✓ Fixed in 1.2.52026-05-28
vulnerable: 0.24.0 ... 1.2.4 (21 versions)
Dulwich is a pure-Python implementation of the Git file formats and protocols. Starting in version 0.24.0 and prior to version 1.2.5, Dulwich's `ProcessMergeDriver` substitutes the file path (from the git tree, controllable by an attacker …
- CVE-2026-47712LOWCVSS 3.3EG 3.3✓ Fixed in 1.2.52026-06-08
vulnerable: 0.24.0 ... 1.2.4 (21 versions)
Dulwich is a pure-Python implementation of the Git file formats and protocols. Starting in version 0.24.0 and prior to version 1.2.5, dulwich.porcelain.format_patch(outdir=...) derives each patch filename from the commit's subject line. Pr…
- CVE-2026-47734MEDIUMCVSS 5.7EG 5.7✓ Fixed in 1.2.52026-06-08
vulnerable: 0.1.0 ... 1.2.4 (166 versions)
Dulwich is a pure-Python implementation of the Git file formats and protocols. Starting in version 0.1.0 and prior to version 1.2.5, a client with push access could push a tiny crafted thin pack (~174 bytes) whose delta header declares a …
Check whether dulwich is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for dulwich CVEs against the assets you own.
Start Free Scan →