---
id: CVE-2026-42305
title: >-
  dulwich: Dulwich: Remote Code Execution via Malicious Git Repository
  (CVE-2026-42305)
summary: >-
  A flaw was found in Dulwich, a pure-Python implementation of the Git file
  formats and protocols. A remote attacker could exploit this vulnerability by
  enticing a user on a Windows system to clone or check out a specially crafted
  malicious …
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'
cvssSource: vendor
cwe: CWE-22
vendor: Red Hat
product: Red Hat OpenShift AI 3.4
affected:
  - ansible_automation_platform 2
  - openshift_ai 3.4
patched:
  - openshift_ai 3.4
published: '2026-06-10'
updated: '2026-09-24'
sourceUpdated: '2026-09-24T14:54:31+00:00'
source: CSAF
sourceUrl: 'https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42305.json'
references:
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42305.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-42305'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2487758'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-42305'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-42305'
  - url: >-
      https://github.com/jelmer/dulwich/commit/49eb56e51aad637fc23d54bf2a08cb42739b8290
  - url: >-
      https://github.com/jelmer/dulwich/commit/57efc4aa1581e038915a0fd79365be53b150f4a9
  - url: 'https://github.com/jelmer/dulwich/releases/tag/dulwich-1.2.5'
  - url: 'https://github.com/jelmer/dulwich/security/advisories/GHSA-897w-fcg9-f6xj'
  - url: 'https://access.redhat.com/errata/RHSA-2026:60520'
  - url: 'https://github.com/jelmer/dulwich'
tags:
  - csaf
  - vex
  - red-hat
  - osv
  - pip
epss: 0.00854
epssPercentile: 0.56559
aliases:
  - GHSA-897w-fcg9-f6xj
  - PYSEC-2026-2463
ecosystem: pip
ingestedAt: '2026-07-13T18:57:54.905Z'
---

## Overview

A flaw was found in Dulwich, a pure-Python implementation of the Git file formats and protocols. A remote attacker could exploit this vulnerability by enticing a user on a Windows system to clone or check out a specially crafted malicious Git repository. This could lead to an arbitrary file write, ultimately resulting in remote code execution on the affected system.

## Vendor advisories

- **RHSA-2026:60520** · Red Hat · fixed in: Red Hat OpenShift AI 3.4 · released 2026-08-27 · [advisory](https://access.redhat.com/errata/RHSA-2026:60520)
- **Red Hat VEX** · Important · affected: Red Hat Ansible Automation Platform 2 · no fix planned: Red Hat Ansible Automation Platform 2 · updated 2026-09-24 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42305.json)

**dulwich: Dulwich: Remote Code Execution via Malicious Git Repository** — rated Important by Red Hat. Released 2026-06-10, updated 2026-09-24.

Affected:

- Red Hat Ansible Automation Platform 2

Fixed:

- Red Hat OpenShift AI 3.4

No fix planned:

- Red Hat Ansible Automation Platform 2

Not affected:

- Red Hat OpenShift AI 3.4
- Red Hat Ansible Automation Platform 2
- Red Hat Enterprise Linux 7
- Red Hat Enterprise Linux 8
- Red Hat OpenShift AI (RHOAI)
- Red Hat OpenShift Container Platform 4
- Red Hat Satellite 6

## Remediation

For Red Hat OpenShift AI 3.4.4 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this errata update:

https://docs.redhat.com/en/documentation/red_hat_openshift_ai/ https://access.redhat.com/errata/RHSA-2026:60520

Workarounds / mitigations:

- Mitigation for this issue involves avoiding the cloning, fetching, or checking out of untrusted Git repositories with Dulwich. This operational control is crucial for preventing the introduction and propagation of malicious content, especially when Red Hat systems interact with or serve Windows clients that utilize Dulwich.

## Package advisory (CVE-2026-42305)

Affected packages:

- `dulwich >= 0.10.0, < 1.2.5`

Patched in:

- `dulwich 1.2.5`

Source: https://osv.dev/vulnerability/GHSA-897w-fcg9-f6xj
