All 5 CVE vulnerabilities found in dulwich, with AI-generated Chinese analysis, references, and POCs.
Vendor: jelmer
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-52726 | Dulwich's submodule path traversal in porcelain.submodule_update / porcelain.clone(recurse_submodules=True) yields RCE via attacker-dropped .git/hooks payload CWE-22 | 7.5 | High | 2026-06-10 |
| CVE-2026-47734 | Dulwich has unbounded memory allocation in receive-pack from crafted thin packs CWE-400 | 5.7 | Medium | 2026-06-10 |
| CVE-2026-47712 | Dulwich doesn't sanitize commit subjects in `porcelain.format_patch` CWE-22 | 3.3 | Low | 2026-06-10 |
| CVE-2026-42305 | Dulwich has an arbitrary file write via NTFS-hostile tree entries on Windows CWE-22 | 8.8 | High | 2026-06-10 |
| CVE-2026-42563 | Dulwich Vulnerable to Command Injection via Merge Driver Path CWE-78 | - | - | 2026-06-10 |
All 5 known CVE vulnerabilities affecting dulwich with full Chinese analysis, references, and POCs where available.