11 Total advisories
11 Vulnerabilities
0 Malware
Dependency scanning
Check whether dulwich is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
HIGH 7.5
CVE-2026-52726
Dulwich's submodule path traversal in porcelain.submodule_update / porcelain.clone(recurse_submodules=True) yields RCE via attacker-dropped .git/hooks payload
LOW 3.3
CVE-2026-47712
Dulwich doesn't sanitize commit subjects in `porcelain.format_patch`
MEDIUM 5.7
CVE-2026-47734
Dulwich has unbounded memory allocation in receive-pack from crafted thin packs
UNKNOWN
CVE-2026-42563
Dulwich Vulnerable to Command Injection via Merge Driver Path
HIGH 8.8
CVE-2026-42305
Dulwich has an arbitrary file write via NTFS-hostile tree entries on Windows
UNKNOWN
CVE-2017-16228
CVE-2017-16228
UNKNOWN
CVE-2014-9706
CVE-2014-9706
UNKNOWN
CVE-2015-0838
CVE-2015-0838
CRITICAL 9.8
CVE-2014-9706
Dulwich Arbitrary code execution via commit with directory path starting with .git
CRITICAL 9.8
CVE-2015-0838
Dulwich Buffer Overflow when handling pack files
CRITICAL 9.8
CVE-2017-16228
Dulwich RCE Vulnerability
Browse more PyPI advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes