CVE-2026-42305 Details
Description
Dulwich is a pure-Python implementation of the Git file formats and protocols. Versions starting with 0.10.0 and prior to 1.2.5 have an arbitrary file write leading to remote code execution when cloning or checking out a malicious Git repository on Windows. Dulwich's path-element validator accepted tree entries whose filenames contained bytes that Windows interprets as structural path syntax. Contributing configuration bugs made matters worse. The core.protectNTFS and core.protectHFS settings were looked up under a wrong option name and so user-set values were silently ignored, and core.protectNTFS only defaulted to true on Windows (Git upstream has defaulted it to true everywhere since CVE-2019-1353). Both have been corrected. Anyone who clones, fetches, or checks out an untrusted repository with Dulwich on Windows - either through the Dulwich CLI, porcelain.clone, or any downstream tool built on Dulwich - is impacted. POSIX clones are not directly exploitable (on POSIX \ is a literal filename byte), but a POSIX user can unknowingly propagate a malicious tree to Windows consumers via push or re-publication. This issue is fixed in Dulwich 1.2.5. Users should upgrade to 1.2.5 or later. There is no effective pre-patch workaround. On affected versions the core.protectNTFS configuration key was silently ignored, so setting it to true does not mitigate the issue. Users who cannot upgrade should avoid cloning, fetching, or checking out untrusted repositories with Dulwich on Windows. After upgrading the NTFS validator is on by default on every platform, so no additional configuration is required.
A vulnerability in Dulwich, a pure-Python implementation of Git file formats and protocols, allows for arbitrary file writes that can lead to remote code execution. This issue affects Dulwich versions 0.10.0 through 1.2.4. The vulnerability arises when cloning or checking out a malicious Git repository on Windows, as Dulwich's path validation accepted filenames that Windows interprets as structural path elements. This flaw, combined with configuration bugs, created a scenario where harmful files could be planted in the user's Git directory, to be executed by Git for Windows, thereby executing arbitrary code in the user's context. While the vulnerability is not directly exploitable on POSIX systems, a POSIX user could inadvertently transfer a malicious repository to a Windows user via Git push or re-publication.
Users are advised to upgrade to Dulwich version 1.2.5 or later. After upgrading, the NTFS path validation is enabled by default on all platforms, eliminating the need for additional configuration.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 10, 2026CISA-ADP
Assessed Jun 11, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/jelmer/dulwich/commit/49eb56e51aad637fc23d54bf2a08cb42739b8290 | [email protected] | Source CodeVendor |
| https://github.com/jelmer/dulwich/commit/57efc4aa1581e038915a0fd79365be53b150f4a9 | [email protected] | Source CodeVendor |
| https://github.com/jelmer/dulwich/releases/tag/dulwich-1.2.5 | [email protected] | Release NotesVendor |
| https://github.com/jelmer/dulwich/security/advisories/GHSA-897w-fcg9-f6xj | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Dulwich | >= 0.10.0, < 1.2.5 (semver) |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 23, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 10, 2026 | New CVE Received | [email protected] |
Volerion