CVE-2026-42563
HighAdvisory
Published 28 May 2026In the index since 6 Sept 2026
- Severity
- High
- worst across findings
- CVSS
- 7.7
- base score, highest
- EPSS
- 0.006
- 45th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 8
- of 17,781 indexed, latest versions
- Container images
- 17
- deployed by those charts
- Fix available
- 1 of 2
- affected packages
Dulwich Vulnerable to Command Injection via Merge Driver Path
Carried by container images the latest versions of 8 of 17,781 indexed charts deploy, on 17 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| dulwichpypi | 0.24.10, 0.25.2, 1.1.0 | 1.2.5 | 9 |
| dulwichdeb | 0.21.6-1build2, 0.22.7-1 | no fix listed | 8 |
- OSV records
- DEBIAN-CVE-2026-42563GHSA-9277-mp7x-85jfUBUNTU-CVE-2026-42563
- Also known as
- PYSEC-2026-2464
Charts affected
8 by stars
| Chart | Latest | Affected images | Radar Score |
|---|---|---|---|
| dependabot-gitlabdependabot-gitlabVerified publisher | 6.3.0 | 1 of 3See more | 4,556 |
| py-kube-downscalerpy-kube-downscalerVerified publisher | 0.3.12 | 1 of 1See more | 731 |
| redminemt190502 | 7.3.4 | 1 of 3See more | 7,527 |
| redmineredmine-helm-chartVerified publisher | 0.2.6 | 1 of 1See more | 4,240 |
| deployhubdeployhubVerified publisher | 10.0.415 | 7 of 11See more | 11,160 |
| osdfir-infrastructureosdfir-infrastructureVerified publisher | 2.15.0 | 5 of 40See more | 71,208 |
| redminerestic-pvc-backupVerified publisher | 0.2.6 | 1 of 1See more | 4,240 |
| servicexssl-hep | 1.8.5 | 1 of 16See more | 66,266 |
Container images carrying it
17 by charts deploying them
A fixed version is listed for 1 of the 2 affected packages.