Junglewise Threat Intelligence

CVE-2026-38974: Dulwich missing SSH host key verification in Paramiko vendor

CVE-2026-38974 · Severity: info · Published 2026-07-15

Technologies: Jelmer Vernooij Dulwich.

Executive brief

Dulwich, a Python-based implementation of the Git protocol, contains a security flaw in its SSH connection handling. The software fails to verify the identity of remote servers when using the Paramiko library, which could allow an attacker to intercept or modify data during Git operations. This puts sensitive source code and credentials at risk of being captured by an unauthorized party during network transfers.

Technical details

A vulnerability exists in Dulwich's 'contrib/paramiko_vendor.py' where SSH host key verification is disabled or missing. By default, the implementation fails to load known hosts or reject unknown keys, which is a violation of secure SSH transport practices. An attacker positioned on the network between the client and the Git server could perform a Man-in-the-Middle (MitM) attack to intercept or alter Git traffic. The issue is addressed in versions following 1.1.0 by properly loading known hosts and enforcing key rejection by default.

Affected products

  • Jelmer Vernooij Dulwich <= 1.1.0

Timeline

  • 2026-03-25: patched: Pull request 2123 merged to fix host key verification.
  • 2026-07-15: disclosed: CVE-2026-38974 published.

References