Where
-Infinity
0

Vendor Risk Score

See how mercurial compares to other vendors in security performance

View Risk Score →

Mercurial 6.9.4 fixes CVE-2025-2361: XSS in hgweb

Mercurial SCMMercurial SCM Web Interface cross site scripting

Risk 27
Severity
5.3
First published (updated )

git-scm GitInput Validation

Risk 89
Severity
9.8
First published (updated )

pip/mercurialMercurial before 1.6.4 fails to verify the Common Name field of SSL certificates which allows remote…

Risk 36
Severity
5.9
First published (updated )

pip/mercurialPath Traversal

Risk 37
Severity
5.9
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

pip/mercurialLast updated 24 July 2024

Risk 69
Severity
9.1
First published (updated )

pip/mercurialInput Validation

Risk 45
Severity
7.5
First published (updated )

redhat/mercurialInput Validation

Risk 46
Severity
7.5
First published (updated )

redhat/mercurialInteger Overflow

Risk 90
Severity
9.8
First published (updated )

Debian Debian LinuxMercurial version 4.5 and earlier contains a Incorrect Access Control (CWE-285) vulnerability in Pro…

Risk 70
Severity
9.1
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Debian Debian LinuxOS Command Injection

Risk 89
Severity
10
First published (updated )

redhat Enterprise Linux Server EusThe symlink auditor is sometimes cached too long, and can be confused into allowing write access to …

Risk 46
Severity
7.5
First published (updated )

redhat Enterprise Linux Server EusOS Command Injection

Risk 91
Severity
10
First published (updated )

redhat Enterprise Linux Server EusIn Mercurial before 4.1.3, "hg serve --stdio" allows remote authenticated users to launch the Python…

Risk 81
Severity
9
First published (updated )

pip/mercurialThe convert extension in Mercurial before 3.8 might allow context-dependent attackers to execute arb…

Risk 80
Severity
8.8
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

SUSE Linux Enterprise Software Development KitInput Validation

Risk 80
Severity
8.8
First published (updated )

SUSE Linux Enterprise Software Development KitInput Validation

Risk 80
Severity
8.8
First published (updated )

SUSE Linux Enterprise Software Development KitThe binary delta decoder in Mercurial before 3.7.3 allows remote attackers to execute arbitrary code…

Risk 80
Severity
8.8
First published (updated )

openSUSE openSUSEInput Validation

Risk 88
Severity
9.8
First published (updated )

Mercurial MercurialMercurial before 1.0.2 does not enforce the allowpull permission setting for a pull operation from h…

Risk 26
Severity
5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

pip/mercurialPath Traversal

Risk 47
Severity
6.8
First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203