Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-38974

Опубликовано: 15 июл. 2026
Источник: redhat
CVSS3: 8.8
EPSS Низкий

Описание

Dulwich through 1.1.0 was found to be missing SSH host key verification in contrib/paramiko_vendor.py.

A flaw was found in Dulwich. The contrib/paramiko_vendor.py component is missing Secure Shell (SSH) host key verification. This vulnerability allows a remote attacker to impersonate a legitimate Git server. By doing so, the attacker could potentially intercept sensitive information or execute arbitrary code on the client system during a connection.

Отчет

This is an Important flaw where Dulwich's paramiko_vendor.py component lacks SSH host key verification. This allows a remote attacker to impersonate a Git server, potentially leading to sensitive data interception or arbitrary code execution on client systems. Exploitation requires user interaction, specifically connecting to a malicious Git server.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Ansible Automation Platform 2ansible-automation-platform-26/controller-rhel9Under investigation
Red Hat Ansible Automation Platform 2ansible-automation-platform-26/eda-controller-rhel9Under investigation
Red Hat Ansible Automation Platform 2ansible-automation-platform-26/lightspeed-chatbot-rhel9Under investigation
Red Hat Ansible Automation Platform 2ansible-automation-platform-27/controller-rhel9Under investigation
Red Hat Ansible Automation Platform 2ansible-automation-platform-27/eda-controller-rhel9Under investigation
Red Hat Enterprise Linux 7resource-agentsUnder investigation
Red Hat OpenShift AI (RHOAI)rhoai/odh-kserve-agent-rhel9Affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-kserve-autogluon-server-rhel9Affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-kserve-controller-rhel9Affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-kserve-router-rhel9Affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-322
https://bugzilla.redhat.com/show_bug.cgi?id=2501226dulwich: Dulwich: Missing SSH host key verification allows potential impersonation

EPSS

Процентиль: 4%
0.00145
Низкий

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
27 дней назад

Dulwich through 1.1.0 was found to be missing SSH host key verification in contrib/paramiko_vendor.py.

CVSS3: 5.3
nvd
27 дней назад

Dulwich through 1.1.0 was found to be missing SSH host key verification in contrib/paramiko_vendor.py.

CVSS3: 5.3
debian
27 дней назад

Dulwich through 1.1.0 was found to be missing SSH host key verificatio ...

suse-cvrf
8 дней назад

Security update for python3-dulwich

suse-cvrf
13 дней назад

Security update for python-dulwich

EPSS

Процентиль: 4%
0.00145
Низкий

8.8 High

CVSS3