CVE-2026-38974

Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.

Dulwich through 1.1.0 was found to be missing SSH host key verification in contrib/paramiko_vendor.py.

Published 2026-07-15. Last modified 2026-07-16.