Dulwich Project maintains a pure-Python implementation of the Git version-control system, a narrowly scoped library that appears across development and deployment toolchains where Git operations are embedded programmatically. Its observed vulnerability signal centers on memory-safety and data-handling concerns, reflected in reports of buffer boundary violations and insufficient input validation, typical of protocol parsers operating on untrusted repository data. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Dulwich Project over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-16228CRITICAL Dulwich before 0.18.5, when an SSH subprocess is used, allows remote attackers to execute arbitrary commands via an ssh URL with an initial dash character in the hostname, a relate | Oct 29, 2017 | 9.8 | 30 | NO | NO |
CVE-2014-9706HIGH The build_index_from_tree function in index.py in Dulwich before 0.9.9 allows remote attackers to execute arbitrary code via a commit with a directory path starting with .git/, whi | Mar 31, 2015 | 7.5 | 21 | NO | NO |
CVE-2015-0838HIGH Buffer overflow in the C implementation of the apply_delta function in _pack.c in Dulwich before 0.9.9 allows remote attackers to execute arbitrary code via a crafted pack file. | Mar 31, 2015 | 7.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Dulwich Project.
Media articles that mention a CVE ID that affects a product developed by Dulwich Project — matched by CVE ID, not by vendor name.