PT-2026-60333 · Pypi · Dulwich

CVE-2026-38974

·

Published

2026-07-15

·

Updated

2026-08-03

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Dulwich versions prior to 1.1.0
Description Dulwich fails to perform SSH host key verification within the contrib/paramiko vendor.py file. This lack of verification allows for potential man-in-the-middle attacks during SSH connections.
Recommendations Update to a version later than 1.1.0. As a temporary mitigation, restrict the use of the contrib/paramiko vendor.py module.

Exploit

Fix

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-92481
CVE-2026-38974
SUSE-SU-2026:3408-1
SUSE-SU-2026:3459-1

Affected Products

Dulwich