MEDIUM5.9
PYSEC-2026-665
Mercurial Improper Certificate Validation vulnerability
Quick fix
PYSEC-2026-665 — mercurial: upgrade to the fixed version with the command below.
pip install --upgrade 'mercurial>=1.6.4'Details
Mercurial before 1.6.4 fails to verify the Common Name field of SSL certificates which allows remote attackers who acquire a certificate signed by a Certificate Authority to perform a man-in-the-middle attack.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2010-4237[ADVISORY]
- https://github.com/dscho/hg/commit/4ea63fb25ceeeaaa4cd1026f733b7ea7672c30b3[WEB]
- https://github.com/dscho/hg/commit/89baabf4fb7abf30ef6fdcf3d455a7893e5cc145[WEB]
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=598841[WEB]
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2010-4237[WEB]
- https://bz.mercurial-scm.org/show_bug.cgi?id=2407[WEB]
- https://repo.mercurial-scm.org/hg/rev/6ab4a7d3c179[WEB]
- https://repo.mercurial-scm.org/hg/rev/f2937d6492c5[WEB]
- https://security-tracker.debian.org/tracker/CVE-2010-4237[WEB]
- https://pypi.org/project/mercurial[PACKAGE]
- https://github.com/advisories/GHSA-7gf7-7wx4-mxmw[ADVISORY]