Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2535▼ 358 respecto a la semana anterior
Críticas / altas1340▲ 76 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
9 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.33% | — | DulwichAIParamikoAI | 15/7/2026 | 16/7/2026 | Dulwich through 1.1.0 was found to be missing SSH host key verification in contrib/paramiko_vendor.py. | |
| Aplazada | Alta (7.5) | 0.68% | — | DulwichAI | 10/6/2026 | 21/7/2026 | Dulwich is a pure-Python implementation of the Git file formats and protocols. Starting in version 0.23.2 and prior to version 1.2.5, `dulwich.porcelain.submodule_update`, and by extension `porcelain.clone(..., recurse_submodules=True)`, materializes attacker-controlled submodule paths from a crafted upstream… | |
| Aplazada | Media (5.7) | 0.33% | — | DulwichAI | 10/6/2026 | 23/7/2026 | Dulwich is a pure-Python implementation of the Git file formats and protocols. Starting in version 0.1.0 and prior to version 1.2.5, a client with push access could push a tiny crafted thin pack (~174 bytes) whose delta header declares a huge dest_size. When dulwich ingested it via add_thin_pack / apply_delta, it… | |
| Aplazada | Baja (3.3) | 0.18% | — | DulwichAI | 10/6/2026 | 21/7/2026 | Dulwich is a pure-Python implementation of the Git file formats and protocols. Starting in version 0.24.0 and prior to version 1.2.5, dulwich.porcelain.format_patch(outdir=...) derives each patch filename from the commit's subject line. Prior to this fix, get_summary only replaced spaces with dashes - path separators… | |
| Aplazada | Alta (7.7) | 0.80% | — | DulwichAI | 10/6/2026 | 21/7/2026 | Dulwich is a pure-Python implementation of the Git file formats and protocols. Starting in version 0.24.0 and prior to version 1.2.5, Dulwich's `ProcessMergeDriver` substitutes the file path (from the git tree, controllable by an attacker via a malicious branch) into the merge driver command via the `%P` placeholder… | |
| Aplazada | Alta (8.8) | 0.85% | — | DulwichAI | 10/6/2026 | 23/7/2026 | Dulwich is a pure-Python implementation of the Git file formats and protocols. Versions starting with 0.10.0 and prior to 1.2.5 have an arbitrary file write leading to remote code execution when cloning or checking out a malicious Git repository on Windows. Dulwich's path-element validator accepted tree entries whose… | |
| Modificada | Crítica (9.8) | 3.7% | — | Dulwich Project Dulwich | 29/10/2017 | 17/6/2026 | Dulwich before 0.18.5, when an SSH subprocess is used, allows remote attackers to execute arbitrary commands via an ssh URL with an initial dash character in the hostname, a related issue to CVE-2017-9800, CVE-2017-12836, CVE-2017-12976, CVE-2017-1000116, and CVE-2017-1000117. | |
| Modificada | Alta (7.5) | 3.4% | — | Debian LinuxDulwich Project Dulwich | 31/3/2015 | 17/6/2026 | Buffer overflow in the C implementation of the apply_delta function in _pack.c in Dulwich before 0.9.9 allows remote attackers to execute arbitrary code via a crafted pack file. | |
| Modificada | Alta (7.5) | 5.0% | — | Debian LinuxDulwich Project Dulwich | 31/3/2015 | 17/6/2026 | The build_index_from_tree function in index.py in Dulwich before 0.9.9 allows remote attackers to execute arbitrary code via a commit with a directory path starting with .git/, which is not properly handled when checking out a working tree. |