Dulwich Arbitrary code execution via commit with directory path starting with .git
Modified: 5/14/2026
package
pkg:pypi/dulwich
Dulwich Arbitrary code execution via commit with directory path starting with .git
Modified: 5/14/2026
Dulwich doesn't sanitize commit subjects in `porcelain.format_patch`
Modified: 7/13/2026
Dulwich has an arbitrary file write via NTFS-hostile tree entries on Windows
Modified: 9/10/2026
Dulwich Vulnerable to Command Injection via Merge Driver Path
Modified: 9/10/2026
Dulwich RCE Vulnerability
Modified: 11/30/2024
Dulwich's submodule path traversal in porcelain.submodule_update / porcelain.clone(recurse_submodules=True) yields RCE via attacker-dropped .git/hooks payload
Modified: 7/13/2026
Dulwich Buffer Overflow when handling pack files
Modified: 4/14/2025
Dulwich has unbounded memory allocation in receive-pack from crafted thin packs
Modified: 7/13/2026
Modified: 6/10/2026
Modified: 6/10/2026
Modified: 6/10/2026
Dulwich doesn't sanitize commit subjects in `porcelain.format_patch`
Modified: 7/13/2026
Dulwich has an arbitrary file write via NTFS-hostile tree entries on Windows
Modified: 7/13/2026
Dulwich Vulnerable to Command Injection via Merge Driver Path
Modified: 7/13/2026
Dulwich's submodule path traversal in porcelain.submodule_update / porcelain.clone(recurse_submodules=True) yields RCE via attacker-dropped .git/hooks payload
Modified: 7/13/2026
Dulwich has unbounded memory allocation in receive-pack from crafted thin packs
Modified: 7/13/2026