CVE-2026-47734
Dulwich is a pure-Python implementation of the Git file formats and protocols. Starting in version 0.1.0 and prior to version 1.2.5, a client with push access could push a tiny crafted thin pack (~174 bytes) whose delta header declares a huge dest_size. When dulwich ingested it via add_thin_pack / apply_delta, it would allocate hundreds of MB of memory based on that attacker-controlled size, with no relationship to the actual bytes received.
Leer descripción completaMostrar menos
Operators running a Dulwich-based Git server that exposes git-receive-pack (i.e. accepts pushes) - for example via dulwich.server functionality, the HTTP smart server, or anything built on ReceivePackHandler - are impacted. The issue is patched in 1.2.5. add_thin_pack now accepts a max_input_size keyword (bytes; 0/None = unlimited, matching git's semantics), and ReceivePackHandler reads receive.maxInputSize from the repository config and passes it through. Wire reads are counted and a PackInputTooLarge exception is raised once the cap is exceeded - equivalent to git index-pack --max-input-size. Users should upgrade to Dulwich 1.2.5 or later and set receive.maxInputSize in their server's repository config to a sane bound for their environment. On unpatched versions, receive.maxInputSize has no effect, so it cannot be used as a workaround. Until upgrading, operators should restrict dulwich-receive-pack (push) access to trusted, authenticated clients only, or disable it entirely on servers that only need to serve fetches and/or run the server under an OS-level memory limit (e.g. ulimit, cgroups/MemoryMax, or a container memory limit) so a malicious push is killed rather than taking down the host.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H
- Puntuación base: 5.7
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.33%
- Percentil entre todas las CVEs puntuadas: 24
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
CWE
- CWE-400, CWE-789
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-47734",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-47734",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2026-06-11T14:08:10.796596Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 5.7,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H",
"integrityImpact": "NONE",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "NONE"
},
"impactScore": 3.6,
"exploitabilityScore": 2.1
}
]
},
"affected": [
{
"source": "security-advisories@github.com",
"affectedData": [
{
"vendor": "jelmer",
"product": "dulwich",
"versions": [
{
"status": "affected",
"version": ">= 0.1.0, < 1.2.5"
}
]
}
]
}
],
"published": "2026-06-10T23:16:48.807",
"references": [
{
"url": "https://github.com/jelmer/dulwich/releases/tag/dulwich-1.2.5",
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/jelmer/dulwich/security/advisories/GHSA-xrvj-v92f-53gj",
"source": "security-advisories@github.com"
}
],
"vulnStatus": "Deferred",
"weaknesses": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"description": [
{
"lang": "en",
"value": "CWE-400"
},
{
"lang": "en",
"value": "CWE-789"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Dulwich is a pure-Python implementation of the Git file formats and protocols. Starting in version 0.1.0 and prior to version 1.2.5, a client with push access could push a tiny crafted thin pack (~174 bytes) whose delta header declares a huge dest_size. When dulwich ingested it via add_thin_pack / apply_delta, it would allocate hundreds of MB of memory based on that attacker-controlled size, with no relationship to the actual bytes received. Operators running a Dulwich-based Git server that exposes git-receive-pack (i.e. accepts pushes) - for example via dulwich.server functionality, the HTTP smart server, or anything built on ReceivePackHandler - are impacted. The issue is patched in 1.2.5. add_thin_pack now accepts a max_input_size keyword (bytes; 0/None = unlimited, matching git's semantics), and ReceivePackHandler reads receive.maxInputSize from the repository config and passes it through. Wire reads are counted and a PackInputTooLarge exception is raised once the cap is exceeded - equivalent to git index-pack --max-input-size. Users should upgrade to Dulwich 1.2.5 or later and set receive.maxInputSize in their server's repository config to a sane bound for their environment. On unpatched versions, receive.maxInputSize has no effect, so it cannot be used as a workaround. Until upgrading, operators should restrict dulwich-receive-pack (push) access to trusted, authenticated clients only, or disable it entirely on servers that only need to serve fetches and/or run the server under an OS-level memory limit (e.g. ulimit, cgroups/MemoryMax, or a container memory limit) so a malicious push is killed rather than taking down the host."
},
{
"lang": "es",
"value": "Dulwich es una implementación pura de Python de los formatos de archivo y protocolos de Git. A partir de la versión 0.1.0 y antes de la versión 1.2.5, un cliente con acceso de push podría enviar un paquete delgado ('thin pack') pequeño y manipulado (~174 bytes) cuyo encabezado delta declara un 'dest_size' enorme. Cuando Dulwich lo ingería a través de 'add_thin_pack' / 'apply_delta', asignaría cientos de MB de memoria basándose en ese tamaño controlado por el atacante, sin relación con los bytes reales recibidos. Los operadores que ejecutan un servidor Git basado en Dulwich que expone 'git-receive-pack' (es decir, acepta 'pushes') - por ejemplo, a través de la funcionalidad 'dulwich.server', el 'smart server' HTTP, o cualquier cosa construida sobre 'ReceivePackHandler' - se ven afectados. El problema está parcheado en la versión 1.2.5. 'add_thin_pack' ahora acepta una palabra clave 'max_input_size' (bytes; 0/None = ilimitado, coincidiendo con la semántica de Git), y 'ReceivePackHandler' lee 'receive.maxInputSize' de la configuración del repositorio y lo pasa. Las lecturas de la red ('wire reads') se cuentan y se lanza una excepción 'PackInputTooLarge' una vez que se excede el límite - equivalente a 'git index-pack --max-input-size'. Los usuarios deben actualizar a Dulwich 1.2.5 o posterior y establecer 'receive.maxInputSize' en la configuración del repositorio de su servidor a un límite razonable para su entorno. En versiones sin parchear, 'receive.maxInputSize' no tiene efecto, por lo que no puede usarse como una solución alternativa. Hasta la actualización, los operadores deben restringir el acceso a 'dulwich-receive-pack' ('push') solo a clientes confiables y autenticados, o deshabilitarlo por completo en servidores que solo necesitan servir 'fetches' y/o ejecutar el servidor bajo un límite de memoria a nivel de sistema operativo (por ejemplo, 'ulimit', 'cgroups/MemoryMax', o un límite de memoria de contenedor) para que un 'push' malicioso sea terminado en lugar de derribar el host."
}
],
"lastModified": "2026-07-23T09:10:00.113",
"sourceIdentifier": "security-advisories@github.com"
}