Vulnerable Library - dulwich-0.20.23-cp37-cp37m-manylinux_2_5_x86_64.manylinux1_x86_64.manylinux_2_12_x86_64.manylinux2010_x86_64.whl
Python Git Library
Library home page: https://files.pythonhosted.org/packages/04/f0/dab35f0491fa36cfc28abd48f150885a08a8726900da25549dbd461bf115/dulwich-0.20.23-cp37-cp37m-manylinux_2_5_x86_64.manylinux1_x86_64.manylinux_2_12_x86_64.manylinux2010_x86_64.whl
Sample Path to Dependency File: /data-files/benchmarks/bm_dulwich_log/requirements.txt
Path to vulnerable library: /data-files/benchmarks/bm_dulwich_log/requirements.txt
Found in HEAD commit: b4e24341e4c07ef7401fadd16a39617d287a4d1e
Vulnerabilities
| Vulnerability |
Severity |
CVSS |
Dependency |
Type |
Fixed in (dulwich version) |
Remediation Possible** |
| CVE-2026-42305 |
High |
8.8 |
dulwich-0.20.23-cp37-cp37m-manylinux_2_5_x86_64.manylinux1_x86_64.manylinux_2_12_x86_64.manylinux2010_x86_64.whl |
Direct |
dulwich - 1.2.5 |
❌ |
| CVE-2026-47734 |
Medium |
5.7 |
dulwich-0.20.23-cp37-cp37m-manylinux_2_5_x86_64.manylinux1_x86_64.manylinux_2_12_x86_64.manylinux2010_x86_64.whl |
Direct |
dulwich - 1.2.5 |
❌ |
| CVE-2026-38974 |
Medium |
5.3 |
dulwich-0.20.23-cp37-cp37m-manylinux_2_5_x86_64.manylinux1_x86_64.manylinux_2_12_x86_64.manylinux2010_x86_64.whl |
Direct |
1.2.0 |
✅ |
**In some cases, Remediation PR cannot be created automatically for a vulnerability despite the availability of remediation
Details
CVE-2026-42305
Vulnerable Library - dulwich-0.20.23-cp37-cp37m-manylinux_2_5_x86_64.manylinux1_x86_64.manylinux_2_12_x86_64.manylinux2010_x86_64.whl
Python Git Library
Library home page: https://files.pythonhosted.org/packages/04/f0/dab35f0491fa36cfc28abd48f150885a08a8726900da25549dbd461bf115/dulwich-0.20.23-cp37-cp37m-manylinux_2_5_x86_64.manylinux1_x86_64.manylinux_2_12_x86_64.manylinux2010_x86_64.whl
Sample Path to Dependency File: /data-files/benchmarks/bm_dulwich_log/requirements.txt
Path to vulnerable library: /data-files/benchmarks/bm_dulwich_log/requirements.txt
Dependency Hierarchy:
- ❌ dulwich-0.20.23-cp37-cp37m-manylinux_2_5_x86_64.manylinux1_x86_64.manylinux_2_12_x86_64.manylinux2010_x86_64.whl (Vulnerable Library)
Found in HEAD commit: b4e24341e4c07ef7401fadd16a39617d287a4d1e
Found in base branch: main
Vulnerability Details
Dulwich is a pure-Python implementation of the Git file formats and protocols. Versions starting with 0.10.0 and prior to 1.2.5 have an arbitrary file write leading to remote code execution when cloning or checking out a malicious Git repository on Windows. Dulwich's path-element validator accepted tree entries whose filenames contained bytes that Windows interprets as structural path syntax. Contributing configuration bugs made matters worse. The core.protectNTFS and core.protectHFS settings were looked up under a wrong option name and so user-set values were silently ignored, and core.protectNTFS only defaulted to true on Windows (Git upstream has defaulted it to true everywhere since CVE-2019-1353). Both have been corrected. Anyone who clones, fetches, or checks out an untrusted repository with Dulwich on Windows - either through the Dulwich CLI, porcelain.clone, or any downstream tool built on Dulwich - is impacted. POSIX clones are not directly exploitable (on POSIX \ is a literal filename byte), but a POSIX user can unknowingly propagate a malicious tree to Windows consumers via push or re-publication. This issue is fixed in Dulwich 1.2.5. Users should upgrade to 1.2.5 or later. There is no effective pre-patch workaround. On affected versions the core.protectNTFS configuration key was silently ignored, so setting it to true does not mitigate the issue. Users who cannot upgrade should avoid cloning, fetching, or checking out untrusted repositories with Dulwich on Windows. After upgrading the NTFS validator is on by default on every platform, so no additional configuration is required.
Publish Date: 2026-06-10
URL: CVE-2026-42305
CVSS 3 Score Details (8.8)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: Required
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: High
For more information on CVSS3 Scores, click here.
Suggested Fix
Type: Upgrade version
Origin: GHSA-897w-fcg9-f6xj
Release Date: 2026-06-10
Fix Resolution: dulwich - 1.2.5
CVE-2026-47734
Vulnerable Library - dulwich-0.20.23-cp37-cp37m-manylinux_2_5_x86_64.manylinux1_x86_64.manylinux_2_12_x86_64.manylinux2010_x86_64.whl
Python Git Library
Library home page: https://files.pythonhosted.org/packages/04/f0/dab35f0491fa36cfc28abd48f150885a08a8726900da25549dbd461bf115/dulwich-0.20.23-cp37-cp37m-manylinux_2_5_x86_64.manylinux1_x86_64.manylinux_2_12_x86_64.manylinux2010_x86_64.whl
Sample Path to Dependency File: /data-files/benchmarks/bm_dulwich_log/requirements.txt
Path to vulnerable library: /data-files/benchmarks/bm_dulwich_log/requirements.txt
Dependency Hierarchy:
- ❌ dulwich-0.20.23-cp37-cp37m-manylinux_2_5_x86_64.manylinux1_x86_64.manylinux_2_12_x86_64.manylinux2010_x86_64.whl (Vulnerable Library)
Found in HEAD commit: b4e24341e4c07ef7401fadd16a39617d287a4d1e
Found in base branch: main
Vulnerability Details
Dulwich is a pure-Python implementation of the Git file formats and protocols. Starting in version 0.1.0 and prior to version 1.2.5, a client with push access could push a tiny crafted thin pack (~174 bytes) whose delta header declares a huge dest_size. When dulwich ingested it via add_thin_pack / apply_delta, it would allocate hundreds of MB of memory based on that attacker-controlled size, with no relationship to the actual bytes received. Operators running a Dulwich-based Git server that exposes git-receive-pack (i.e. accepts pushes) - for example via dulwich.server functionality, the HTTP smart server, or anything built on ReceivePackHandler - are impacted. The issue is patched in 1.2.5. add_thin_pack now accepts a max_input_size keyword (bytes; 0/None = unlimited, matching git's semantics), and ReceivePackHandler reads receive.maxInputSize from the repository config and passes it through. Wire reads are counted and a PackInputTooLarge exception is raised once the cap is exceeded - equivalent to git index-pack --max-input-size. Users should upgrade to Dulwich 1.2.5 or later and set receive.maxInputSize in their server's repository config to a sane bound for their environment. On unpatched versions, receive.maxInputSize has no effect, so it cannot be used as a workaround. Until upgrading, operators should restrict dulwich-receive-pack (push) access to trusted, authenticated clients only, or disable it entirely on servers that only need to serve fetches and/or run the server under an OS-level memory limit (e.g. ulimit, cgroups/MemoryMax, or a container memory limit) so a malicious push is killed rather than taking down the host.
Publish Date: 2026-06-10
URL: CVE-2026-47734
CVSS 3 Score Details (5.7)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: Low
- User Interaction: Required
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: None
- Integrity Impact: None
- Availability Impact: High
For more information on CVSS3 Scores, click here.
Suggested Fix
Type: Upgrade version
Origin: GHSA-xrvj-v92f-53gj
Release Date: 2026-06-09
Fix Resolution: dulwich - 1.2.5
CVE-2026-38974
Vulnerable Library - dulwich-0.20.23-cp37-cp37m-manylinux_2_5_x86_64.manylinux1_x86_64.manylinux_2_12_x86_64.manylinux2010_x86_64.whl
Python Git Library
Library home page: https://files.pythonhosted.org/packages/04/f0/dab35f0491fa36cfc28abd48f150885a08a8726900da25549dbd461bf115/dulwich-0.20.23-cp37-cp37m-manylinux_2_5_x86_64.manylinux1_x86_64.manylinux_2_12_x86_64.manylinux2010_x86_64.whl
Sample Path to Dependency File: /data-files/benchmarks/bm_dulwich_log/requirements.txt
Path to vulnerable library: /data-files/benchmarks/bm_dulwich_log/requirements.txt
Dependency Hierarchy:
- ❌ dulwich-0.20.23-cp37-cp37m-manylinux_2_5_x86_64.manylinux1_x86_64.manylinux_2_12_x86_64.manylinux2010_x86_64.whl (Vulnerable Library)
Found in HEAD commit: b4e24341e4c07ef7401fadd16a39617d287a4d1e
Found in base branch: main
Vulnerability Details
Dulwich through 1.1.0 was found to be missing SSH host key verification in contrib/paramiko_vendor.py.
Publish Date: 2026-07-15
URL: CVE-2026-38974
CVSS 3 Score Details (5.3)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: Low
- Integrity Impact: None
- Availability Impact: None
For more information on CVSS3 Scores, click here.
Suggested Fix
Type: Upgrade version
Release Date: 2026-07-15
Fix Resolution: 1.2.0
⛑️ Automatic Remediation will be attempted for this issue.
⛑️Automatic Remediation will be attempted for this issue.
Python Git Library
Library home page: https://files.pythonhosted.org/packages/04/f0/dab35f0491fa36cfc28abd48f150885a08a8726900da25549dbd461bf115/dulwich-0.20.23-cp37-cp37m-manylinux_2_5_x86_64.manylinux1_x86_64.manylinux_2_12_x86_64.manylinux2010_x86_64.whl
Sample Path to Dependency File: /data-files/benchmarks/bm_dulwich_log/requirements.txt
Path to vulnerable library: /data-files/benchmarks/bm_dulwich_log/requirements.txt
Found in HEAD commit: b4e24341e4c07ef7401fadd16a39617d287a4d1e
Vulnerabilities
**In some cases, Remediation PR cannot be created automatically for a vulnerability despite the availability of remediation
Details
Vulnerable Library - dulwich-0.20.23-cp37-cp37m-manylinux_2_5_x86_64.manylinux1_x86_64.manylinux_2_12_x86_64.manylinux2010_x86_64.whl
Python Git Library
Library home page: https://files.pythonhosted.org/packages/04/f0/dab35f0491fa36cfc28abd48f150885a08a8726900da25549dbd461bf115/dulwich-0.20.23-cp37-cp37m-manylinux_2_5_x86_64.manylinux1_x86_64.manylinux_2_12_x86_64.manylinux2010_x86_64.whl
Sample Path to Dependency File: /data-files/benchmarks/bm_dulwich_log/requirements.txt
Path to vulnerable library: /data-files/benchmarks/bm_dulwich_log/requirements.txt
Dependency Hierarchy:
Found in HEAD commit: b4e24341e4c07ef7401fadd16a39617d287a4d1e
Found in base branch: main
Vulnerability Details
Dulwich is a pure-Python implementation of the Git file formats and protocols. Versions starting with 0.10.0 and prior to 1.2.5 have an arbitrary file write leading to remote code execution when cloning or checking out a malicious Git repository on Windows. Dulwich's path-element validator accepted tree entries whose filenames contained bytes that Windows interprets as structural path syntax. Contributing configuration bugs made matters worse. The core.protectNTFS and core.protectHFS settings were looked up under a wrong option name and so user-set values were silently ignored, and core.protectNTFS only defaulted to true on Windows (Git upstream has defaulted it to true everywhere since CVE-2019-1353). Both have been corrected. Anyone who clones, fetches, or checks out an untrusted repository with Dulwich on Windows - either through the Dulwich CLI, porcelain.clone, or any downstream tool built on Dulwich - is impacted. POSIX clones are not directly exploitable (on POSIX \ is a literal filename byte), but a POSIX user can unknowingly propagate a malicious tree to Windows consumers via push or re-publication. This issue is fixed in Dulwich 1.2.5. Users should upgrade to 1.2.5 or later. There is no effective pre-patch workaround. On affected versions the core.protectNTFS configuration key was silently ignored, so setting it to true does not mitigate the issue. Users who cannot upgrade should avoid cloning, fetching, or checking out untrusted repositories with Dulwich on Windows. After upgrading the NTFS validator is on by default on every platform, so no additional configuration is required.
Publish Date: 2026-06-10
URL: CVE-2026-42305
CVSS 3 Score Details (8.8)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: Required
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: High
For more information on CVSS3 Scores, click here.Suggested Fix
Type: Upgrade version
Origin: GHSA-897w-fcg9-f6xj
Release Date: 2026-06-10
Fix Resolution: dulwich - 1.2.5
Vulnerable Library - dulwich-0.20.23-cp37-cp37m-manylinux_2_5_x86_64.manylinux1_x86_64.manylinux_2_12_x86_64.manylinux2010_x86_64.whl
Python Git Library
Library home page: https://files.pythonhosted.org/packages/04/f0/dab35f0491fa36cfc28abd48f150885a08a8726900da25549dbd461bf115/dulwich-0.20.23-cp37-cp37m-manylinux_2_5_x86_64.manylinux1_x86_64.manylinux_2_12_x86_64.manylinux2010_x86_64.whl
Sample Path to Dependency File: /data-files/benchmarks/bm_dulwich_log/requirements.txt
Path to vulnerable library: /data-files/benchmarks/bm_dulwich_log/requirements.txt
Dependency Hierarchy:
Found in HEAD commit: b4e24341e4c07ef7401fadd16a39617d287a4d1e
Found in base branch: main
Vulnerability Details
Dulwich is a pure-Python implementation of the Git file formats and protocols. Starting in version 0.1.0 and prior to version 1.2.5, a client with push access could push a tiny crafted thin pack (~174 bytes) whose delta header declares a huge dest_size. When dulwich ingested it via add_thin_pack / apply_delta, it would allocate hundreds of MB of memory based on that attacker-controlled size, with no relationship to the actual bytes received. Operators running a Dulwich-based Git server that exposes git-receive-pack (i.e. accepts pushes) - for example via dulwich.server functionality, the HTTP smart server, or anything built on ReceivePackHandler - are impacted. The issue is patched in 1.2.5. add_thin_pack now accepts a max_input_size keyword (bytes; 0/None = unlimited, matching git's semantics), and ReceivePackHandler reads receive.maxInputSize from the repository config and passes it through. Wire reads are counted and a PackInputTooLarge exception is raised once the cap is exceeded - equivalent to git index-pack --max-input-size. Users should upgrade to Dulwich 1.2.5 or later and set receive.maxInputSize in their server's repository config to a sane bound for their environment. On unpatched versions, receive.maxInputSize has no effect, so it cannot be used as a workaround. Until upgrading, operators should restrict dulwich-receive-pack (push) access to trusted, authenticated clients only, or disable it entirely on servers that only need to serve fetches and/or run the server under an OS-level memory limit (e.g. ulimit, cgroups/MemoryMax, or a container memory limit) so a malicious push is killed rather than taking down the host.
Publish Date: 2026-06-10
URL: CVE-2026-47734
CVSS 3 Score Details (5.7)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: Low
- User Interaction: Required
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: None
- Integrity Impact: None
- Availability Impact: High
For more information on CVSS3 Scores, click here.Suggested Fix
Type: Upgrade version
Origin: GHSA-xrvj-v92f-53gj
Release Date: 2026-06-09
Fix Resolution: dulwich - 1.2.5
Vulnerable Library - dulwich-0.20.23-cp37-cp37m-manylinux_2_5_x86_64.manylinux1_x86_64.manylinux_2_12_x86_64.manylinux2010_x86_64.whl
Python Git Library
Library home page: https://files.pythonhosted.org/packages/04/f0/dab35f0491fa36cfc28abd48f150885a08a8726900da25549dbd461bf115/dulwich-0.20.23-cp37-cp37m-manylinux_2_5_x86_64.manylinux1_x86_64.manylinux_2_12_x86_64.manylinux2010_x86_64.whl
Sample Path to Dependency File: /data-files/benchmarks/bm_dulwich_log/requirements.txt
Path to vulnerable library: /data-files/benchmarks/bm_dulwich_log/requirements.txt
Dependency Hierarchy:
Found in HEAD commit: b4e24341e4c07ef7401fadd16a39617d287a4d1e
Found in base branch: main
Vulnerability Details
Dulwich through 1.1.0 was found to be missing SSH host key verification in contrib/paramiko_vendor.py.
Publish Date: 2026-07-15
URL: CVE-2026-38974
CVSS 3 Score Details (5.3)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: Low
- Integrity Impact: None
- Availability Impact: None
For more information on CVSS3 Scores, click here.Suggested Fix
Type: Upgrade version
Release Date: 2026-07-15
Fix Resolution: 1.2.0
⛑️ Automatic Remediation will be attempted for this issue.
⛑️Automatic Remediation will be attempted for this issue.