---
id: CVE-2010-4237
aliases:
  - GHSA-7gf7-7wx4-mxmw
  - PYSEC-2026-665
title: Mercurial Improper Certificate Validation vulnerability
summary: Mercurial Improper Certificate Validation vulnerability
severity: medium
cvss: 5.9
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N'
vendor: mercurial
product: mercurial
ecosystem: pip
affected:
  - mercurial < 1.6.4
patched:
  - mercurial 1.6.4
published: '2022-04-21'
updated: '2026-07-06'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-7gf7-7wx4-mxmw'
references:
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2010-4237'
  - url: >-
      https://github.com/dscho/hg/commit/4ea63fb25ceeeaaa4cd1026f733b7ea7672c30b3
  - url: >-
      https://github.com/dscho/hg/commit/89baabf4fb7abf30ef6fdcf3d455a7893e5cc145
  - url: 'https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=598841'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2010-4237'
  - url: 'https://bz.mercurial-scm.org/show_bug.cgi?id=2407'
  - url: 'https://repo.mercurial-scm.org/hg/rev/6ab4a7d3c179'
  - url: 'https://repo.mercurial-scm.org/hg/rev/f2937d6492c5'
  - url: 'https://security-tracker.debian.org/tracker/CVE-2010-4237'
tags:
  - osv
  - pip
epss: 0.00821
epssPercentile: 0.55749
ingestedAt: '2026-07-08T18:25:46.994Z'
---

## Overview

Mercurial before 1.6.4 fails to verify the Common Name field of SSL certificates which allows remote attackers who acquire a certificate signed by a Certificate Authority to perform a man-in-the-middle attack.

## Affected packages

- `mercurial < 1.6.4`

## Remediation

Upgrade to a patched release:

- `mercurial 1.6.4`
