© 2025-2026 PySpect
First version without a known vulnerability: 1.2.5
Dulwich's submodule path traversal in porcelain.submodule_update / porcelain.clone(recurse_submodules=True) yields RCE via attacker-dropped .git/hooks payload
Fixed in: 1.2.5
Dulwich has unbounded memory allocation in receive-pack from crafted thin packs
Fixed in: 1.2.5
Dulwich doesn't sanitize commit subjects in `porcelain.format_patch`
Fixed in: 1.2.5
Dulwich Vulnerable to Command Injection via Merge Driver Path
Fixed in: 1.2.5
Dulwich has an arbitrary file write via NTFS-hostile tree entries on Windows
Fixed in: 1.2.5
Dulwich Buffer Overflow when handling pack files
Fixed in: 0.9.9
Dulwich Arbitrary code execution via commit with directory path starting with .git
Fixed in: 0.9.10, 0.9.9
Dulwich RCE Vulnerability
Fixed in: 0.18.5