Technology · PyPI
mercurial (PyPI) vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 18 vulnerabilities in mercurial (PyPI): 0 in the last 7 days and 2 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2008-2942, was published on 2 July 2026.
- Last 7 days
- 0
- Last 90 days
- 2
- Critical, all time
- 0
- Exploited in the wild
- 0
Latest mercurial (PyPI) vulnerabilities
- CVE-2008-2942: PYSEC-2026-666 - Mercurial Directory traversal vulnerabilityinfoEPSS 1.9%
- CVE-2010-4237: PYSEC-2026-665 - Mercurial Improper Certificate Validation vulnerabilitylowCVSS 3.1EPSS 0.8%
- CVE-2014-9390: PYSEC-2020-217 - Git before 1.8.5.6, 1.9.x before 1.9.5, 2.0.x before 2.0.5, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 on…lowCVSS 3.1EPSS 75.6%
- CVE-2019-3902: PYSEC-2019-188 - A flaw was found in Mercurial before 4.9. It was possible to use symlinks and subrepositories to defeat…lowCVSS 3EPSS 1.4%
- CVE-2018-17983: PYSEC-2018-91 - cext/manifest.c in Mercurial before 4.7.2 has an out-of-bounds read during parsing of a malformed manifest…lowCVSS 3EPSS 2.1%
- CVE-2018-13346: PYSEC-2018-88 - The mpatch_apply function in mpatch.c in Mercurial before 4.6.1 incorrectly proceeds in cases where the…lowCVSS 3EPSS 2.4%
- CVE-2018-13348: PYSEC-2018-90 - The mpatch_decode function in mpatch.c in Mercurial before 4.6.1 mishandles certain situations where there…lowCVSS 3EPSS 2.1%
- CVE-2018-13347: PYSEC-2018-89 - mpatch.c in Mercurial before 4.6.1 mishandles integer addition and subtraction, aka OVE-20180430-0002.lowCVSS 3EPSS 2.7%
- CVE-2018-1000132: PYSEC-2018-87 - Mercurial version 4.5 and earlier contains a Incorrect Access Control (CWE-285) vulnerability in…lowCVSS 3EPSS 2.6%
- CVE-2017-17458: PYSEC-2017-90 - In Mercurial before 4.4.1, it is possible that a specially malformed repository can cause Git…lowCVSS 3EPSS 6.3%
- CVE-2017-1000116: PYSEC-2017-89 - Mercurial prior to 4.3 did not adequately sanitize hostnames passed to ssh, leading to possible…lowCVSS 3EPSS 5.7%
- CVE-2017-1000115: PYSEC-2017-88 - Mercurial prior to version 4.3 is vulnerable to a missing symlink check that can malicious repositories…lowCVSS 3EPSS 4.8%
- CVE-2017-9462: PYSEC-2017-91 - In Mercurial before 4.1.3, "hg serve --stdio" allows remote authenticated users to launch the Python…lowCVSS 3.1EPSS 21.7%
- CVE-2016-3105: PYSEC-2016-28 - The convert extension in Mercurial before 3.8 might allow context-dependent attackers to execute arbitrary…lowCVSS 3EPSS 2.7%
- CVE-2016-3069: PYSEC-2016-27 - Mercurial before 3.7.3 allows remote attackers to execute arbitrary code via a crafted name when converting…lowCVSS 3EPSS 5.0%
- CVE-2016-3630: PYSEC-2016-29 - The binary delta decoder in Mercurial before 3.7.3 allows remote attackers to execute arbitrary code via a…lowCVSS 3EPSS 4.9%
- CVE-2016-3068: PYSEC-2016-26 - Mercurial before 3.7.3 allows remote attackers to execute arbitrary code via a crafted git ext:: URL when…lowCVSS 3EPSS 5.4%
- CVE-2014-9462: PYSEC-2015-14 - The _validaterepo function in sshpeer in Mercurial before 3.2.4 allows remote attackers to execute…lowCVSS 3.1EPSS 4.2%
Most severe mercurial (PyPI) vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2014-9390: PYSEC-2020-217 - Git before 1.8.5.6, 1.9.x before 1.9.5, 2.0.x before 2.0.5, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 on…lowCVSS 3.1EPSS 75.6%
- CVE-2017-9462: PYSEC-2017-91 - In Mercurial before 4.1.3, "hg serve --stdio" allows remote authenticated users to launch the Python…lowCVSS 3.1EPSS 21.7%
- CVE-2014-9462: PYSEC-2015-14 - The _validaterepo function in sshpeer in Mercurial before 3.2.4 allows remote attackers to execute…lowCVSS 3.1EPSS 4.2%
- CVE-2010-4237: PYSEC-2026-665 - Mercurial Improper Certificate Validation vulnerabilitylowCVSS 3.1EPSS 0.8%
- CVE-2017-17458: PYSEC-2017-90 - In Mercurial before 4.4.1, it is possible that a specially malformed repository can cause Git…lowCVSS 3EPSS 6.3%
- CVE-2017-1000116: PYSEC-2017-89 - Mercurial prior to 4.3 did not adequately sanitize hostnames passed to ssh, leading to possible…lowCVSS 3EPSS 5.7%
- CVE-2016-3068: PYSEC-2016-26 - Mercurial before 3.7.3 allows remote attackers to execute arbitrary code via a crafted git ext:: URL when…lowCVSS 3EPSS 5.4%
- CVE-2016-3069: PYSEC-2016-27 - Mercurial before 3.7.3 allows remote attackers to execute arbitrary code via a crafted name when converting…lowCVSS 3EPSS 5.0%
- CVE-2016-3630: PYSEC-2016-29 - The binary delta decoder in Mercurial before 3.7.3 allows remote attackers to execute arbitrary code via a…lowCVSS 3EPSS 4.9%
- CVE-2017-1000115: PYSEC-2017-88 - Mercurial prior to version 4.3 is vulnerable to a missing symlink check that can malicious repositories…lowCVSS 3EPSS 4.8%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 2 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/mercurial.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "mercurial (PyPI) vulnerabilities", https://junglewise.ai/threats/technologies/mercurial, 26 September 2026.