{"schema_version":1,"title":"mercurial (PyPI) vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 18 vulnerabilities in mercurial (PyPI): 0 in the last 7 days and 2 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2008-2942, was published on 2 July 2026.","url":"https://junglewise.ai/threats/technologies/mercurial","json_url":"https://junglewise.ai/threats/technologies/mercurial.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/mercurial","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":0,"all_time":18,"critical":0,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":2,"last_365_days":2},"latest":[{"cve":"CVE-2008-2942","epss":0.019,"slug":"cve-2008-2942-mercurial-directory-traversal-vulnerability","title":"PYSEC-2026-666 - Mercurial Directory traversal vulnerability","severity":"info","exploited":false,"published_at":"2026-07-02T14:13:21.096985+00:00","url":"https://junglewise.ai/threats/cve-2008-2942-mercurial-directory-traversal-vulnerability"},{"cve":"CVE-2010-4237","cvss":3.1,"epss":0.0082,"slug":"cve-2010-4237-mercurial-improper-certificate-validation-vulnerability","title":"PYSEC-2026-665 - Mercurial Improper Certificate Validation vulnerability","severity":"low","exploited":false,"published_at":"2026-07-02T14:13:17.606556+00:00","url":"https://junglewise.ai/threats/cve-2010-4237-mercurial-improper-certificate-validation-vulnerability"},{"cve":"CVE-2014-9390","cvss":3.1,"epss":0.756,"slug":"cve-2014-9390-jgit-improper-input-validation-vulnerability","title":"PYSEC-2020-217 - Git before 1.8.5.6, 1.9.x before 1.9.5, 2.0.x before 2.0.5, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 on Windows and OS X; Mercurial before","severity":"low","exploited":false,"published_at":"2020-02-12T02:15:00+00:00","url":"https://junglewise.ai/threats/cve-2014-9390-jgit-improper-input-validation-vulnerability"},{"cve":"CVE-2019-3902","cvss":3,"epss":0.0143,"slug":"cve-2019-3902-mercurial-path-traversal-link-following-vulnerability","title":"PYSEC-2019-188 - A flaw was found in Mercurial before 4.9. It was possible to use symlinks and subrepositories to defeat Mercurial's path-checking logic and","severity":"low","exploited":false,"published_at":"2019-04-22T16:29:00+00:00","url":"https://junglewise.ai/threats/cve-2019-3902-mercurial-path-traversal-link-following-vulnerability"},{"cve":"CVE-2018-17983","cvss":3,"epss":0.0205,"slug":"cve-2018-17983-mercurial-out-of-bounds-read-vulnerability","title":"PYSEC-2018-91 - cext/manifest.c in Mercurial before 4.7.2 has an out-of-bounds read during parsing of a malformed manifest entry.","severity":"low","exploited":false,"published_at":"2018-10-04T23:29:00+00:00","url":"https://junglewise.ai/threats/cve-2018-17983-mercurial-out-of-bounds-read-vulnerability"},{"cve":"CVE-2018-13346","cvss":3,"epss":0.0236,"slug":"cve-2018-13346-mercurial-improper-input-validation-vulnerability","title":"PYSEC-2018-88 - The mpatch_apply function in mpatch.c in Mercurial before 4.6.1 incorrectly proceeds in cases where the fragment start is past the end of th","severity":"low","exploited":false,"published_at":"2018-07-06T00:29:00+00:00","url":"https://junglewise.ai/threats/cve-2018-13346-mercurial-improper-input-validation-vulnerability"},{"cve":"CVE-2018-13348","cvss":3,"epss":0.021,"slug":"cve-2018-13348-mercurial-improper-input-validation-vulnerability","title":"PYSEC-2018-90 - The mpatch_decode function in mpatch.c in Mercurial before 4.6.1 mishandles certain situations where there should be at least 12 bytes remai","severity":"low","exploited":false,"published_at":"2018-07-06T00:29:00+00:00","url":"https://junglewise.ai/threats/cve-2018-13348-mercurial-improper-input-validation-vulnerability"},{"cve":"CVE-2018-13347","cvss":3,"epss":0.0267,"slug":"cve-2018-13347-mercurial-integer-overflow-in-mpatch-c","title":"PYSEC-2018-89 - mpatch.c in Mercurial before 4.6.1 mishandles integer addition and subtraction, aka OVE-20180430-0002.","severity":"low","exploited":false,"published_at":"2018-07-06T00:29:00+00:00","url":"https://junglewise.ai/threats/cve-2018-13347-mercurial-integer-overflow-in-mpatch-c"},{"cve":"CVE-2018-1000132","cvss":3,"epss":0.0262,"slug":"cve-2018-1000132-mercurial-incorrect-access-control-vulnerability","title":"PYSEC-2018-87 - Mercurial version 4.5 and earlier contains a Incorrect Access Control (CWE-285) vulnerability in Protocol server that can result in Unauthor","severity":"low","exploited":false,"published_at":"2018-03-14T13:29:00+00:00","url":"https://junglewise.ai/threats/cve-2018-1000132-mercurial-incorrect-access-control-vulnerability"},{"cve":"CVE-2017-17458","cvss":3,"epss":0.0633,"slug":"cve-2017-17458-mercurial-vulnerable-to-arbitrary-code-injection","title":"PYSEC-2017-90 - In Mercurial before 4.4.1, it is possible that a specially malformed repository can cause Git subrepositories to run arbitrary code in the f","severity":"low","exploited":false,"published_at":"2017-12-07T18:29:00+00:00","url":"https://junglewise.ai/threats/cve-2017-17458-mercurial-vulnerable-to-arbitrary-code-injection"},{"cve":"CVE-2017-1000116","cvss":3,"epss":0.0573,"slug":"cve-2017-1000116-mercurial-is-vulnerable-to-shell-injection-attack","title":"PYSEC-2017-89 - Mercurial prior to 4.3 did not adequately sanitize hostnames passed to ssh, leading to possible shell-injection attacks.","severity":"low","exploited":false,"published_at":"2017-10-05T01:29:00+00:00","url":"https://junglewise.ai/threats/cve-2017-1000116-mercurial-is-vulnerable-to-shell-injection-attack"},{"cve":"CVE-2017-1000115","cvss":3,"epss":0.0482,"slug":"cve-2017-1000115-mercurial-missing-symlink-check","title":"PYSEC-2017-88 - Mercurial prior to version 4.3 is vulnerable to a missing symlink check that can malicious repositories to modify files outside the reposito","severity":"low","exploited":false,"published_at":"2017-10-05T01:29:00+00:00","url":"https://junglewise.ai/threats/cve-2017-1000115-mercurial-missing-symlink-check"},{"cve":"CVE-2017-9462","cvss":3.1,"epss":0.2169,"slug":"cve-2017-9462-mercurial-has-incorrect-permission-assignment-for-critical","title":"PYSEC-2017-91 - In Mercurial before 4.1.3, \"hg serve --stdio\" allows remote authenticated users to launch the Python debugger, and consequently execute arbi","severity":"low","exploited":false,"published_at":"2017-06-06T21:29:00+00:00","url":"https://junglewise.ai/threats/cve-2017-9462-mercurial-has-incorrect-permission-assignment-for-critical"},{"cve":"CVE-2016-3105","cvss":3,"epss":0.0266,"slug":"cve-2016-3105-mercurial-vulnerable-to-arbitrary-code-execution-when-converting","title":"PYSEC-2016-28 - The convert extension in Mercurial before 3.8 might allow context-dependent attackers to execute arbitrary code via a crafted git repository","severity":"low","exploited":false,"published_at":"2016-05-09T20:59:00+00:00","url":"https://junglewise.ai/threats/cve-2016-3105-mercurial-vulnerable-to-arbitrary-code-execution-when-converting"},{"cve":"CVE-2016-3069","cvss":3,"epss":0.0495,"slug":"cve-2016-3069-mercurial-vulnerable-to-arbitrary-code-execution-via-a-crafted","title":"PYSEC-2016-27 - Mercurial before 3.7.3 allows remote attackers to execute arbitrary code via a crafted name when converting a Git repository.","severity":"low","exploited":false,"published_at":"2016-04-13T16:59:00+00:00","url":"https://junglewise.ai/threats/cve-2016-3069-mercurial-vulnerable-to-arbitrary-code-execution-via-a-crafted"},{"cve":"CVE-2016-3630","cvss":3,"epss":0.0487,"slug":"cve-2016-3630-mercurial-arbitrary-code-execution-vulnerability","title":"PYSEC-2016-29 - The binary delta decoder in Mercurial before 3.7.3 allows remote attackers to execute arbitrary code via a (1) clone, (2) push, or (3) pull","severity":"low","exploited":false,"published_at":"2016-04-13T16:59:00+00:00","url":"https://junglewise.ai/threats/cve-2016-3630-mercurial-arbitrary-code-execution-vulnerability"},{"cve":"CVE-2016-3068","cvss":3,"epss":0.0541,"slug":"cve-2016-3068-mercurial-arbitrary-code-execution-via-a-crafted-git-ext-url","title":"PYSEC-2016-26 - Mercurial before 3.7.3 allows remote attackers to execute arbitrary code via a crafted git ext:: URL when cloning a subrepository.","severity":"low","exploited":false,"published_at":"2016-04-13T16:59:00+00:00","url":"https://junglewise.ai/threats/cve-2016-3068-mercurial-arbitrary-code-execution-via-a-crafted-git-ext-url"},{"cve":"CVE-2014-9462","cvss":3.1,"epss":0.0417,"slug":"cve-2014-9462-mercurial-arbitrary-command-execution-via-crafted-repository-name","title":"PYSEC-2015-14 - The _validaterepo function in sshpeer in Mercurial before 3.2.4 allows remote attackers to execute arbitrary commands via a crafted reposito","severity":"low","exploited":false,"published_at":"2015-03-31T14:59:00+00:00","url":"https://junglewise.ai/threats/cve-2014-9462-mercurial-arbitrary-command-execution-via-crafted-repository-name"}],"weekly":[{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-28","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"tensorflow (PyPI)","slug":"pypi-tensorflow","vulnerabilities":428,"url":"https://junglewise.ai/threats/technologies/pypi-tensorflow"},{"name":"tensorflow-cpu (PyPI)","slug":"tensorflow-cpu","vulnerabilities":424,"url":"https://junglewise.ai/threats/technologies/tensorflow-cpu"},{"name":"tensorflow-gpu (PyPI)","slug":"tensorflow-gpu","vulnerabilities":421,"url":"https://junglewise.ai/threats/technologies/tensorflow-gpu"},{"name":"open-webui (PyPI)","slug":"open-webui","vulnerabilities":177,"url":"https://junglewise.ai/threats/technologies/open-webui"},{"name":"Django (PyPI)","slug":"django","vulnerabilities":172,"url":"https://junglewise.ai/threats/technologies/django"},{"name":"apache-airflow (PyPI)","slug":"apache-airflow","vulnerabilities":152,"url":"https://junglewise.ai/threats/technologies/apache-airflow"},{"name":"plone (PyPI)","slug":"pypi-plone","vulnerabilities":101,"url":"https://junglewise.ai/threats/technologies/pypi-plone"},{"name":"praisonai (PyPI)","slug":"pypi-praisonai","vulnerabilities":86,"url":"https://junglewise.ai/threats/technologies/pypi-praisonai"},{"name":"exiv2 (PyPI)","slug":"exiv2","vulnerabilities":85,"url":"https://junglewise.ai/threats/technologies/exiv2"},{"name":"nltk (PyPI)","slug":"nltk","vulnerabilities":83,"url":"https://junglewise.ai/threats/technologies/nltk"},{"name":"mlflow (PyPI)","slug":"mlflow","vulnerabilities":82,"url":"https://junglewise.ai/threats/technologies/mlflow"},{"name":"pillow (PyPI)","slug":"pillow","vulnerabilities":79,"url":"https://junglewise.ai/threats/technologies/pillow"}],"technology":{"hub":true,"name":"mercurial (PyPI)","slug":"mercurial","vendor":{"name":"PyPI","slug":"pypi","url":"https://junglewise.ai/threats/vendors/pypi"},"aliases":[],"description":"Mercurial is a distributed version control system for source code management.","url":"https://junglewise.ai/threats/technologies/mercurial"},"most_severe":[{"cve":"CVE-2014-9390","cvss":3.1,"epss":0.756,"slug":"cve-2014-9390-jgit-improper-input-validation-vulnerability","title":"PYSEC-2020-217 - Git before 1.8.5.6, 1.9.x before 1.9.5, 2.0.x before 2.0.5, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 on Windows and OS X; Mercurial before","severity":"low","exploited":false,"published_at":"2020-02-12T02:15:00+00:00","url":"https://junglewise.ai/threats/cve-2014-9390-jgit-improper-input-validation-vulnerability"},{"cve":"CVE-2017-9462","cvss":3.1,"epss":0.2169,"slug":"cve-2017-9462-mercurial-has-incorrect-permission-assignment-for-critical","title":"PYSEC-2017-91 - In Mercurial before 4.1.3, \"hg serve --stdio\" allows remote authenticated users to launch the Python debugger, and consequently execute arbi","severity":"low","exploited":false,"published_at":"2017-06-06T21:29:00+00:00","url":"https://junglewise.ai/threats/cve-2017-9462-mercurial-has-incorrect-permission-assignment-for-critical"},{"cve":"CVE-2014-9462","cvss":3.1,"epss":0.0417,"slug":"cve-2014-9462-mercurial-arbitrary-command-execution-via-crafted-repository-name","title":"PYSEC-2015-14 - The _validaterepo function in sshpeer in Mercurial before 3.2.4 allows remote attackers to execute arbitrary commands via a crafted reposito","severity":"low","exploited":false,"published_at":"2015-03-31T14:59:00+00:00","url":"https://junglewise.ai/threats/cve-2014-9462-mercurial-arbitrary-command-execution-via-crafted-repository-name"},{"cve":"CVE-2010-4237","cvss":3.1,"epss":0.0082,"slug":"cve-2010-4237-mercurial-improper-certificate-validation-vulnerability","title":"PYSEC-2026-665 - Mercurial Improper Certificate Validation vulnerability","severity":"low","exploited":false,"published_at":"2026-07-02T14:13:17.606556+00:00","url":"https://junglewise.ai/threats/cve-2010-4237-mercurial-improper-certificate-validation-vulnerability"},{"cve":"CVE-2017-17458","cvss":3,"epss":0.0633,"slug":"cve-2017-17458-mercurial-vulnerable-to-arbitrary-code-injection","title":"PYSEC-2017-90 - In Mercurial before 4.4.1, it is possible that a specially malformed repository can cause Git subrepositories to run arbitrary code in the f","severity":"low","exploited":false,"published_at":"2017-12-07T18:29:00+00:00","url":"https://junglewise.ai/threats/cve-2017-17458-mercurial-vulnerable-to-arbitrary-code-injection"},{"cve":"CVE-2017-1000116","cvss":3,"epss":0.0573,"slug":"cve-2017-1000116-mercurial-is-vulnerable-to-shell-injection-attack","title":"PYSEC-2017-89 - Mercurial prior to 4.3 did not adequately sanitize hostnames passed to ssh, leading to possible shell-injection attacks.","severity":"low","exploited":false,"published_at":"2017-10-05T01:29:00+00:00","url":"https://junglewise.ai/threats/cve-2017-1000116-mercurial-is-vulnerable-to-shell-injection-attack"},{"cve":"CVE-2016-3068","cvss":3,"epss":0.0541,"slug":"cve-2016-3068-mercurial-arbitrary-code-execution-via-a-crafted-git-ext-url","title":"PYSEC-2016-26 - Mercurial before 3.7.3 allows remote attackers to execute arbitrary code via a crafted git ext:: URL when cloning a subrepository.","severity":"low","exploited":false,"published_at":"2016-04-13T16:59:00+00:00","url":"https://junglewise.ai/threats/cve-2016-3068-mercurial-arbitrary-code-execution-via-a-crafted-git-ext-url"},{"cve":"CVE-2016-3069","cvss":3,"epss":0.0495,"slug":"cve-2016-3069-mercurial-vulnerable-to-arbitrary-code-execution-via-a-crafted","title":"PYSEC-2016-27 - Mercurial before 3.7.3 allows remote attackers to execute arbitrary code via a crafted name when converting a Git repository.","severity":"low","exploited":false,"published_at":"2016-04-13T16:59:00+00:00","url":"https://junglewise.ai/threats/cve-2016-3069-mercurial-vulnerable-to-arbitrary-code-execution-via-a-crafted"},{"cve":"CVE-2016-3630","cvss":3,"epss":0.0487,"slug":"cve-2016-3630-mercurial-arbitrary-code-execution-vulnerability","title":"PYSEC-2016-29 - The binary delta decoder in Mercurial before 3.7.3 allows remote attackers to execute arbitrary code via a (1) clone, (2) push, or (3) pull","severity":"low","exploited":false,"published_at":"2016-04-13T16:59:00+00:00","url":"https://junglewise.ai/threats/cve-2016-3630-mercurial-arbitrary-code-execution-vulnerability"},{"cve":"CVE-2017-1000115","cvss":3,"epss":0.0482,"slug":"cve-2017-1000115-mercurial-missing-symlink-check","title":"PYSEC-2017-88 - Mercurial prior to version 4.3 is vulnerable to a missing symlink check that can malicious repositories to modify files outside the reposito","severity":"low","exploited":false,"published_at":"2017-10-05T01:29:00+00:00","url":"https://junglewise.ai/threats/cve-2017-1000115-mercurial-missing-symlink-check"}],"generated_at":"2026-09-28T03:07:00.154823+00:00"}