dulwich vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-52726Highdulwich: Dulwich's submodule path traversal in porcelain.submodule_update / porcelain.clone(recurse_submodules=True) yields RCE via attacker-dropped…CVE-2026-47734Mediumdulwich: Dulwich has unbounded memory allocation in receive-pack from crafted thin packsCVE-2026-47712Lowdulwich: Dulwich doesn't sanitize commit subjects in `porcelain.format_patch`CVE-2026-42563Highdulwich: Dulwich Vulnerable to Command Injection via Merge Driver PathCVE-2026-42305Highdulwich: Dulwich has an arbitrary file write via NTFS-hostile tree entries on WindowsCVE-2015-0838Criticaldulwich: Dulwich Buffer Overflow when handling pack filesCVE-2014-9706Criticaldulwich: Dulwich Arbitrary code execution via commit with directory path starting with .gitCVE-2017-16228Criticaldulwich: Dulwich RCE Vulnerability

Stop the waste.
Protect your environment with Kodem.