CVE-2017-16228: Dulwich Project Dulwich
Critical severity, CVSS 9.8. EPSS: 3.8% chance of exploitation in the next 30 days.
Dulwich before 0.18.5, when an SSH subprocess is used, allows remote attackers to execute arbitrary commands via an ssh URL with an initial dash character in the hostname, a related issue to CVE-2017-9800, CVE-2017-12836, CVE-2017-12976, CVE-2017-1000116, and CVE-2017-1000117.
Affected products
- Dulwich Project Dulwich: up to and including 0.18.4
Published 2017-10-29. Last modified 2026-06-17.