DEBIAN-CVE-2026-42563

Source
https://security-tracker.debian.org/tracker/CVE-2026-42563
Import Source
https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2026-42563.json
JSON Data
https://api.test.osv.dev/v1/vulns/DEBIAN-CVE-2026-42563
Upstream
Published
2026-06-10T23:16:46Z
Modified
2026-09-01T16:06:42Z
Severity
  • 7.7 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X CVSS Calculator
Summary
[none]
Details

Dulwich is a pure-Python implementation of the Git file formats and protocols. Starting in version 0.24.0 and prior to version 1.2.5, Dulwich's ProcessMergeDriver substitutes the file path (from the git tree, controllable by an attacker via a malicious branch) into the merge driver command via the %P placeholder and executes it with subprocess.run(..., shell=True). An attacker who can cause a victim to merge an untrusted branch can achieve arbitrary command execution by crafting malicious file paths. Version 1.2.5 fixes the issue.

References

Affected packages

Debian:12 / dulwich

Package

Name
dulwich
Purl
pkg:deb/debian/dulwich?arch=source&distro=bookworm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

0.*
0.21.2-1
0.21.5-1
0.21.6-1
0.22.5-1
0.22.7-1
0.22.7-2
0.24.2-1
0.24.2-2
0.24.10-1
1.*
1.0.0-1
1.0.0-2
1.1.0-1
1.1.0-2
1.1.0-3
1.2.0-1
1.2.1-1
1.2.5-1
1.2.7-1
1.2.7-2
1.2.11-1
1.2.12-1

Ecosystem specific

{
    "urgency":  "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2026-42563.json"

Debian:13 / dulwich

Package

Name
dulwich
Purl
pkg:deb/debian/dulwich?arch=source&distro=trixie

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

0.*
0.22.7-1
0.22.7-2
0.24.2-1
0.24.2-2
0.24.10-1
1.*
1.0.0-1
1.0.0-2
1.1.0-1
1.1.0-2
1.1.0-3
1.2.0-1
1.2.1-1
1.2.5-1
1.2.7-1
1.2.7-2
1.2.11-1
1.2.12-1

Ecosystem specific

{
    "urgency":  "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2026-42563.json"

Debian:14 / dulwich

Package

Name
dulwich
Purl
pkg:deb/debian/dulwich?arch=source&distro=forky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.2.5-1

Affected versions

0.*
0.22.7-1
0.22.7-2
0.24.2-1
0.24.2-2
0.24.10-1
1.*
1.0.0-1
1.0.0-2
1.1.0-1
1.1.0-2
1.1.0-3
1.2.0-1
1.2.1-1

Ecosystem specific

{
    "urgency":  "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2026-42563.json"