CVE-2026-42305
Last modified
CVE-2026-42305 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. Dulwich is a pure-Python implementation of the Git file formats and protocols. Versions starting with 0.10.0 and prior to 1.2.5 have an arbitrary file write leading to remote code execution when cloning or checking out a malicious Git repository on Windows. EPSS estimates a 0.64% chance of exploitation in the next 30 days.
Description
Dulwich is a pure-Python implementation of the Git file formats and protocols. Versions starting with 0.10.0 and prior to 1.2.5 have an arbitrary file write leading to remote code execution when cloning or checking out a malicious Git repository on Windows. Dulwich's path-element validator accepted tree entries whose filenames contained bytes that Windows interprets as structural path syntax. Contributing configuration bugs made matters worse. The core.protectNTFS and core.protectHFS settings were looked up under a wrong option name and so user-set values were silently ignored, and core.protectNTFS only defaulted to true on Windows (Git upstream has defaulted it to true everywhere since CVE-2019-1353). Both have been corrected. Anyone who clones, fetches, or checks out an untrusted repository with Dulwich on Windows - either through the Dulwich CLI, porcelain.clone, or any downstream tool built on Dulwich - is impacted. POSIX clones are not directly exploitable (on POSIX \ is a literal filename byte), but a POSIX user can unknowingly propagate a malicious tree to Windows consumers via push or re-publication. This issue is fixed in Dulwich 1.2.5. Users should upgrade to 1.2.5 or later. There is no effective pre-patch workaround. On affected versions the core.protectNTFS configuration key was silently ignored, so setting it to true does not mitigate the issue. Users who cannot upgrade should avoid cloning, fetching, or checking out untrusted repositories with Dulwich on Windows. After upgrading the NTFS validator is on by default on every platform, so no additional configuration is required.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-42305?
How severe is CVE-2026-42305?
How do I fix CVE-2026-42305?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-4230A vulnerability has been found in vanna-ai vanna up to 2.0.2…6.3
- CVE-2026-42300DevGuard provides vulnerability management for the full soft…9.3
- CVE-2026-42301pyp2spec generates working Fedora RPM spec file for Python p…7.8
- CVE-2026-42302FastGPT is an AI Agent building platform. From version 4.14.…9.8
- CVE-2026-42303Fides is an open-source privacy engineering platform. From 2…6.1
- CVE-2026-42304Twisted is an event-based framework for internet application…7.5
- CVE-2026-42306Moby is an open source container framework. In Docker Engine…7.2
- CVE-2026-42307Vim is an open source, command line text editor. Prior to ve…4.4
- CVE-2026-42308Pillow is a Python imaging library. Prior to version 12.2.0,…5.5
- CVE-2026-42309Pillow is a Python imaging library. From version 11.2.1 to b…5.5
- CVE-2026-4231A vulnerability was found in vanna-ai vanna up to 2.0.2. Aff…7.3
- CVE-2026-42310Pillow is a Python imaging library. From version 4.2.0 to be…5.5
Are you affected by CVE-2026-42305?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
