Technology · PyPI
dulwich (PyPI) vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 9 vulnerabilities in dulwich (PyPI): 0 in the last 7 days and 1 in the last 90 days, 1 of them critical and 0 exploited in the wild. The most recent, CVE-2026-38974, was published on 15 July 2026.
- Last 7 days
- 0
- Last 90 days
- 1
- Critical, all time
- 1
- Exploited in the wild
- 0
About dulwich (PyPI)
A pure-Python implementation of the Git file formats and protocols.
Latest dulwich (PyPI) vulnerabilities
- CVE-2026-38974: Dulwich missing SSH host key verification in Paramiko vendorinfo
- CVE-2026-52726: Jelmer Dulwich arbitrary code execution via submodule path traversalhighCVSS 7.5EPSS 0.7%
- CVE-2026-47734: Dulwich uncontrolled memory allocation in git-receive-packmediumCVSS 5.7EPSS 0.3%
- CVE-2026-47712: Dulwich path traversal in porcelain.format_patch via commit subjectlowCVSS 3.3EPSS 0.2%
- CVE-2026-42563: Dulwich OS command injection in ProcessMergeDriverhighCVSS 4EPSS 0.8%
- CVE-2026-42305: Dulwich arbitrary file write and RCE via NTFS-hostile tree entrieshighCVSS 8.8EPSS 0.9%
- CVE-2014-9706: Dulwich arbitrary code execution via malicious .git directory pathscriticalCVSS 9.8EPSS 5.0%
- CVE-2017-16228: PYSEC-2017-12 - Dulwich before 0.18.5, when an SSH subprocess is used, allows remote attackers to execute arbitrary…lowCVSS 3EPSS 3.7%
- CVE-2015-0838: PYSEC-2015-35 - Buffer overflow in the C implementation of the apply_delta function in _pack.c in Dulwich before 0.9.9…lowCVSS 3.1EPSS 3.4%
Most severe dulwich (PyPI) vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2014-9706: Dulwich arbitrary code execution via malicious .git directory pathscriticalCVSS 9.8EPSS 5.0%
- CVE-2026-42305: Dulwich arbitrary file write and RCE via NTFS-hostile tree entrieshighCVSS 8.8EPSS 0.9%
- CVE-2026-52726: Jelmer Dulwich arbitrary code execution via submodule path traversalhighCVSS 7.5EPSS 0.7%
- CVE-2026-42563: Dulwich OS command injection in ProcessMergeDriverhighCVSS 4EPSS 0.8%
- CVE-2026-47734: Dulwich uncontrolled memory allocation in git-receive-packmediumCVSS 5.7EPSS 0.3%
- CVE-2026-47712: Dulwich path traversal in porcelain.format_patch via commit subjectlowCVSS 3.3EPSS 0.2%
- CVE-2015-0838: PYSEC-2015-35 - Buffer overflow in the C implementation of the apply_delta function in _pack.c in Dulwich before 0.9.9…lowCVSS 3.1EPSS 3.4%
- CVE-2017-16228: PYSEC-2017-12 - Dulwich before 0.18.5, when an SSH subprocess is used, allows remote attackers to execute arbitrary…lowCVSS 3EPSS 3.7%
- CVE-2026-38974: Dulwich missing SSH host key verification in Paramiko vendorinfo
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 1 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/dulwich.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "dulwich (PyPI) vulnerabilities", https://junglewise.ai/threats/technologies/dulwich, 26 September 2026.