Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
PYSEC-2026-2465
  • PyPI/dulwich
Dulwich's submodule path traversal in porcelain.submodule_update / porcelain.clone(recurse_submodules=True) yields RCE via attacker-dropped .git/hooks payload 13 Jul
  • Fix available
  • Severity - 7.5 (High)
PYSEC-2026-2466
  • PyPI/dulwich
Dulwich has unbounded memory allocation in receive-pack from crafted thin packs 13 Jul
  • Fix available
  • Severity - 5.7 (Medium)
PYSEC-2026-2462
  • PyPI/dulwich
Dulwich doesn't sanitize commit subjects in `porcelain.format_patch` 13 Jul
  • Fix available
  • Severity - 3.3 (Low)
PYSEC-2026-2464
  • PyPI/dulwich
Dulwich Vulnerable to Command Injection via Merge Driver Path 13 Jul
  • Fix available
  • Severity - 7.7 (High)
PYSEC-2026-2463
  • PyPI/dulwich
Dulwich has an arbitrary file write via NTFS-hostile tree entries on Windows 13 Jul
  • Fix available
  • Severity - 8.8 (High)
GHSA-gfhv-vqv2-4544
  • PyPI/dulwich
Dulwich's submodule path traversal in porcelain.submodule_update / porcelain.clone(recurse_submodules=True) yields RCE via attacker-dropped .git/hooks payload 02 Jul
  • Fix available
  • Severity - 7.5 (High)
GHSA-xrvj-v92f-53gj
  • PyPI/dulwich
Dulwich has unbounded memory allocation in receive-pack from crafted thin packs 08 Jun
  • Fix available
  • Severity - 5.7 (Medium)
GHSA-555p-6grf-mh7f
  • PyPI/dulwich
Dulwich doesn't sanitize commit subjects in `porcelain.format_patch` 08 Jun
  • Fix available
  • Severity - 3.3 (Low)
GHSA-9277-mp7x-85jf
  • PyPI/dulwich
Dulwich Vulnerable to Command Injection via Merge Driver Path 28 May
  • Fix available
  • Severity - 7.7 (High)
GHSA-897w-fcg9-f6xj
  • PyPI/dulwich
Dulwich has an arbitrary file write via NTFS-hostile tree entries on Windows 28 May
  • Fix available
  • Severity - 8.8 (High)
GHSA-vjjf-3rvg-gv3v
  • PyPI/dulwich
Dulwich Buffer Overflow when handling pack files 17 May 2022
  • Fix available
  • Severity - 9.3 (Critical)
GHSA-4j5j-58j7-6c3w
  • PyPI/dulwich
Dulwich Arbitrary code execution via commit with directory path starting with .git 17 May 2022
  • Fix available
  • Severity - 9.3 (Critical)
GHSA-cwwh-4382-6fwr
  • PyPI/dulwich
Dulwich RCE Vulnerability 13 May 2022
  • Fix available
  • Severity - 9.3 (Critical)
PYSEC-2017-12
  • PyPI/dulwich
See record for full details 29 Oct 2017
  • Fix available
PYSEC-2015-34
  • PyPI/dulwich
See record for full details 31 Mar 2015
  • Fix available
PYSEC-2015-35
  • PyPI/dulwich
See record for full details 31 Mar 2015
  • Fix available