{"schema_version":1,"title":"dulwich (PyPI) vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 9 vulnerabilities in dulwich (PyPI): 0 in the last 7 days and 1 in the last 90 days, 1 of them critical and 0 exploited in the wild. The most recent, CVE-2026-38974, was published on 15 July 2026.","url":"https://junglewise.ai/threats/technologies/dulwich","json_url":"https://junglewise.ai/threats/technologies/dulwich.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/dulwich","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":3,"all_time":9,"critical":1,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":1,"last_365_days":6},"latest":[{"cve":"CVE-2026-38974","slug":"cve-2026-38974-dulwich-missing-ssh-host-key-verification-in-paramiko-vendor","title":"Dulwich missing SSH host key verification in Paramiko vendor","severity":"info","exploited":false,"published_at":"2026-07-15T22:16:47.443+00:00","url":"https://junglewise.ai/threats/cve-2026-38974-dulwich-missing-ssh-host-key-verification-in-paramiko-vendor"},{"cve":"CVE-2026-52726","cvss":7.5,"epss":0.0068,"slug":"cve-2026-52726-jelmer-dulwich-arbitrary-code-execution-via-submodule-path","title":"Jelmer Dulwich arbitrary code execution via submodule path traversal","severity":"high","exploited":false,"published_at":"2026-06-10T23:16:50.143+00:00","url":"https://junglewise.ai/threats/cve-2026-52726-jelmer-dulwich-arbitrary-code-execution-via-submodule-path"},{"cve":"CVE-2026-47734","cvss":5.7,"epss":0.0033,"slug":"cve-2026-47734-dulwich-uncontrolled-memory-allocation-in-git-receive-pack","title":"Dulwich uncontrolled memory allocation in git-receive-pack","severity":"medium","exploited":false,"published_at":"2026-06-10T23:16:48.807+00:00","url":"https://junglewise.ai/threats/cve-2026-47734-dulwich-uncontrolled-memory-allocation-in-git-receive-pack"},{"cve":"CVE-2026-47712","cvss":3.3,"epss":0.0018,"slug":"cve-2026-47712-dulwich-path-traversal-in-porcelain-format-patch-via-commit","title":"Dulwich path traversal in porcelain.format_patch via commit subject","severity":"low","exploited":false,"published_at":"2026-06-10T23:16:48.65+00:00","url":"https://junglewise.ai/threats/cve-2026-47712-dulwich-path-traversal-in-porcelain-format-patch-via-commit"},{"cve":"CVE-2026-42563","cvss":4,"epss":0.008,"slug":"cve-2026-42563-dulwich-os-command-injection-in-processmergedriver","title":"Dulwich OS command injection in ProcessMergeDriver","severity":"high","exploited":false,"published_at":"2026-06-10T23:16:46.413+00:00","url":"https://junglewise.ai/threats/cve-2026-42563-dulwich-os-command-injection-in-processmergedriver"},{"cve":"CVE-2026-42305","cvss":8.8,"epss":0.0085,"slug":"cve-2026-42305-dulwich-arbitrary-file-write-and-rce-via-ntfs-hostile-tree","title":"Dulwich arbitrary file write and RCE via NTFS-hostile tree entries","severity":"high","exploited":false,"published_at":"2026-06-10T23:16:46.113+00:00","url":"https://junglewise.ai/threats/cve-2026-42305-dulwich-arbitrary-file-write-and-rce-via-ntfs-hostile-tree"},{"cve":"CVE-2014-9706","cvss":9.8,"epss":0.05,"slug":"cve-2014-9706-dulwich-arbitrary-code-execution-via-malicious-git-directory-paths","title":"Dulwich arbitrary code execution via malicious .git directory paths","severity":"critical","exploited":false,"published_at":"2022-05-17T04:14:03+00:00","url":"https://junglewise.ai/threats/cve-2014-9706-dulwich-arbitrary-code-execution-via-malicious-git-directory-paths"},{"cve":"CVE-2017-16228","cvss":3,"epss":0.0366,"slug":"cve-2017-16228-dulwich-rce-vulnerability","title":"PYSEC-2017-12 - Dulwich before 0.18.5, when an SSH subprocess is used, allows remote attackers to execute arbitrary commands via an ssh URL with an initial","severity":"low","exploited":false,"published_at":"2017-10-29T20:29:00+00:00","url":"https://junglewise.ai/threats/cve-2017-16228-dulwich-rce-vulnerability"},{"cve":"CVE-2015-0838","cvss":3.1,"epss":0.0338,"slug":"cve-2015-0838-dulwich-buffer-overflow-when-handling-pack-files","title":"PYSEC-2015-35 - Buffer overflow in the C implementation of the apply_delta function in _pack.c in Dulwich before 0.9.9 allows remote attackers to execute ar","severity":"low","exploited":false,"published_at":"2015-03-31T14:59:00+00:00","url":"https://junglewise.ai/threats/cve-2015-0838-dulwich-buffer-overflow-when-handling-pack-files"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"open-webui (PyPI)","slug":"open-webui","vulnerabilities":156,"url":"https://junglewise.ai/threats/technologies/open-webui"},{"name":"nltk (PyPI)","slug":"nltk","vulnerabilities":74,"url":"https://junglewise.ai/threats/technologies/nltk"},{"name":"picklescan (PyPI)","slug":"picklescan","vulnerabilities":74,"url":"https://junglewise.ai/threats/technologies/picklescan"},{"name":"openbabel (PyPI)","slug":"openbabel","vulnerabilities":48,"url":"https://junglewise.ai/threats/technologies/openbabel"},{"name":"apache-superset (PyPI)","slug":"apache-superset","vulnerabilities":44,"url":"https://junglewise.ai/threats/technologies/apache-superset"},{"name":"apache-airflow (PyPI)","slug":"apache-airflow","vulnerabilities":40,"url":"https://junglewise.ai/threats/technologies/apache-airflow"},{"name":"tensorflow-gpu (PyPI)","slug":"tensorflow-gpu","vulnerabilities":37,"url":"https://junglewise.ai/threats/technologies/tensorflow-gpu"},{"name":"tensorflow-cpu (PyPI)","slug":"tensorflow-cpu","vulnerabilities":34,"url":"https://junglewise.ai/threats/technologies/tensorflow-cpu"},{"name":"weblate (PyPI)","slug":"weblate","vulnerabilities":33,"url":"https://junglewise.ai/threats/technologies/weblate"},{"name":"mcp-atlassian (PyPI)","slug":"mcp-atlassian","vulnerabilities":30,"url":"https://junglewise.ai/threats/technologies/mcp-atlassian"},{"name":"crawl4ai (PyPI)","slug":"crawl4ai","vulnerabilities":28,"url":"https://junglewise.ai/threats/technologies/crawl4ai"},{"name":"moin (PyPI)","slug":"moin","vulnerabilities":28,"url":"https://junglewise.ai/threats/technologies/moin"}],"technology":{"hub":true,"name":"dulwich (PyPI)","slug":"dulwich","vendor":{"name":"PyPI","slug":"pypi","url":"https://junglewise.ai/threats/vendors/pypi"},"aliases":[],"homepage":"https://www.dulwich.io/","repo_url":"https://github.com/jelmer/dulwich","description":"A pure-Python implementation of the Git file formats and protocols.","url":"https://junglewise.ai/threats/technologies/dulwich"},"most_severe":[{"cve":"CVE-2014-9706","cvss":9.8,"epss":0.05,"slug":"cve-2014-9706-dulwich-arbitrary-code-execution-via-malicious-git-directory-paths","title":"Dulwich arbitrary code execution via malicious .git directory paths","severity":"critical","exploited":false,"published_at":"2022-05-17T04:14:03+00:00","url":"https://junglewise.ai/threats/cve-2014-9706-dulwich-arbitrary-code-execution-via-malicious-git-directory-paths"},{"cve":"CVE-2026-42305","cvss":8.8,"epss":0.0085,"slug":"cve-2026-42305-dulwich-arbitrary-file-write-and-rce-via-ntfs-hostile-tree","title":"Dulwich arbitrary file write and RCE via NTFS-hostile tree entries","severity":"high","exploited":false,"published_at":"2026-06-10T23:16:46.113+00:00","url":"https://junglewise.ai/threats/cve-2026-42305-dulwich-arbitrary-file-write-and-rce-via-ntfs-hostile-tree"},{"cve":"CVE-2026-52726","cvss":7.5,"epss":0.0068,"slug":"cve-2026-52726-jelmer-dulwich-arbitrary-code-execution-via-submodule-path","title":"Jelmer Dulwich arbitrary code execution via submodule path traversal","severity":"high","exploited":false,"published_at":"2026-06-10T23:16:50.143+00:00","url":"https://junglewise.ai/threats/cve-2026-52726-jelmer-dulwich-arbitrary-code-execution-via-submodule-path"},{"cve":"CVE-2026-42563","cvss":4,"epss":0.008,"slug":"cve-2026-42563-dulwich-os-command-injection-in-processmergedriver","title":"Dulwich OS command injection in ProcessMergeDriver","severity":"high","exploited":false,"published_at":"2026-06-10T23:16:46.413+00:00","url":"https://junglewise.ai/threats/cve-2026-42563-dulwich-os-command-injection-in-processmergedriver"},{"cve":"CVE-2026-47734","cvss":5.7,"epss":0.0033,"slug":"cve-2026-47734-dulwich-uncontrolled-memory-allocation-in-git-receive-pack","title":"Dulwich uncontrolled memory allocation in git-receive-pack","severity":"medium","exploited":false,"published_at":"2026-06-10T23:16:48.807+00:00","url":"https://junglewise.ai/threats/cve-2026-47734-dulwich-uncontrolled-memory-allocation-in-git-receive-pack"},{"cve":"CVE-2026-47712","cvss":3.3,"epss":0.0018,"slug":"cve-2026-47712-dulwich-path-traversal-in-porcelain-format-patch-via-commit","title":"Dulwich path traversal in porcelain.format_patch via commit subject","severity":"low","exploited":false,"published_at":"2026-06-10T23:16:48.65+00:00","url":"https://junglewise.ai/threats/cve-2026-47712-dulwich-path-traversal-in-porcelain-format-patch-via-commit"},{"cve":"CVE-2015-0838","cvss":3.1,"epss":0.0338,"slug":"cve-2015-0838-dulwich-buffer-overflow-when-handling-pack-files","title":"PYSEC-2015-35 - Buffer overflow in the C implementation of the apply_delta function in _pack.c in Dulwich before 0.9.9 allows remote attackers to execute ar","severity":"low","exploited":false,"published_at":"2015-03-31T14:59:00+00:00","url":"https://junglewise.ai/threats/cve-2015-0838-dulwich-buffer-overflow-when-handling-pack-files"},{"cve":"CVE-2017-16228","cvss":3,"epss":0.0366,"slug":"cve-2017-16228-dulwich-rce-vulnerability","title":"PYSEC-2017-12 - Dulwich before 0.18.5, when an SSH subprocess is used, allows remote attackers to execute arbitrary commands via an ssh URL with an initial","severity":"low","exploited":false,"published_at":"2017-10-29T20:29:00+00:00","url":"https://junglewise.ai/threats/cve-2017-16228-dulwich-rce-vulnerability"},{"cve":"CVE-2026-38974","slug":"cve-2026-38974-dulwich-missing-ssh-host-key-verification-in-paramiko-vendor","title":"Dulwich missing SSH host key verification in Paramiko vendor","severity":"info","exploited":false,"published_at":"2026-07-15T22:16:47.443+00:00","url":"https://junglewise.ai/threats/cve-2026-38974-dulwich-missing-ssh-host-key-verification-in-paramiko-vendor"}],"generated_at":"2026-09-26T12:07:00.15149+00:00"}