CVEInsight.
TrendingZero-DayExploreBrowseSearchSaved
CVEInsight.

Free vulnerability intelligence for developers, security teams, and researchers. Data sourced from public databases for informational purposes only.

Explore

HomeTrendingZero-Day WatchAttack TypesBrowse CVEsSearch

Legal

Privacy PolicyTerms of ServiceData Disclaimer

© 2026CVEInsight. For informational use only — not a substitute for professional security advice.

CVE data sourced from NVD / NIST & public disclosures.

Search Vulnerabilities

 Software

Searching vulnerabilities affecting “mercurial”

13 vulnerabilities found for “mercurial”

CVE-2022-43410
MEDIUM5.3

Jenkins Mercurial Plugin 1251.va_b_121f184902 and earlier provides information about which jobs were triggered or scheduled for polling through its webhook endpoint, including jobs the user has no permission to access.

jenkins / mercurial
Network
Published Oct 19, 2022
CVE-2022-30948
HIGH7.5

Jenkins Mercurial Plugin 2.16 and earlier allows attackers able to configure pipelines to check out some SCM repositories stored on the Jenkins controller's file system using local paths as SCM URLs, obtaining limited information about other projects' SCM contents.

jenkins / mercurial
Network
Published May 17, 2022
CVE-2020-2305
MEDIUM6.5

Jenkins Mercurial Plugin 2.11 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

jenkins / mercurial
Network
Published Nov 4, 2020
CVE-2020-2306
MEDIUM4.3

A missing permission check in Jenkins Mercurial Plugin 2.11 and earlier allows attackers with Overall/Read permission to obtain a list of names of configured Mercurial installations.

jenkins / mercurial
Network
Published Nov 4, 2020
CVE-2014-9390
CRITICAL9.8

Git before 1.8.5.6, 1.9.x before 1.9.5, 2.0.x before 2.0.5, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 on Windows and OS X; Mercurial before 3.2.3 on Windows and OS X; Apple Xcode before 6.2 beta 3; mine all versions before 08-12-2014; libgit2 all versions up to 0.21.2; Egit all versions before 08-12-2014; and JGit all versions before 08-12-2014 allow remote Git servers to execute arbitrary commands via a tree containing a crafted .git/config file with (1) an ignorable Unicode codepoint, (2) a git~1/config representation, or (3) mixed case that is improperly handled on a case-insensitive filesystem.

git-scm / git+12
Network
Published Feb 12, 2020
CVE-2010-4237
MEDIUM5.9

Mercurial before 1.6.4 fails to verify the Common Name field of SSL certificates which allows remote attackers who acquire a certificate signed by a Certificate Authority to perform a man-in-the-middle attack.

mercurial / mercurial
Network
Published Oct 29, 2019
CVE-2019-3902
MEDIUM5.1

A flaw was found in Mercurial before 4.9. It was possible to use symlinks and subrepositories to defeat Mercurial's path-checking logic and write files outside a repository.

mercurial / mercurial+2
Local
Published Apr 22, 2019
CVE-2018-17983
CRITICAL9.1

cext/manifest.c in Mercurial before 4.7.2 has an out-of-bounds read during parsing of a malformed manifest entry.

mercurial / mercurial
Network
Published Oct 4, 2018
CVE-2018-13348
HIGH7.5

The mpatch_decode function in mpatch.c in Mercurial before 4.6.1 mishandles certain situations where there should be at least 12 bytes remaining after the current position in the patch data, but actually are not, aka OVE-20180430-0001.

mercurial / mercurial
Network
Published Jul 6, 2018
CVE-2018-13346
HIGH7.5

The mpatch_apply function in mpatch.c in Mercurial before 4.6.1 incorrectly proceeds in cases where the fragment start is past the end of the original data, aka OVE-20180430-0004.

mercurial / mercurial
Network
Published Jul 6, 2018
CVE-2018-13347
CRITICAL9.8

mpatch.c in Mercurial before 4.6.1 mishandles integer addition and subtraction, aka OVE-20180430-0002.

mercurial / mercurial
Network
Published Jul 6, 2018
CVE-2018-1000132
CRITICAL9.1

Mercurial version 4.5 and earlier contains a Incorrect Access Control (CWE-285) vulnerability in Protocol server that can result in Unauthorized data access. This attack appear to be exploitable via network connectivity. This vulnerability appears to have been fixed in 4.5.1.

mercurial / mercurial+2
Network
Published Mar 14, 2018
CVE-2018-1000112
MEDIUM5.3

An improper authorization vulnerability exists in Jenkins Mercurial Plugin version 2.2 and earlier in MercurialStatus.java that allows an attacker with network access to obtain a list of nodes and users.

jenkins / mercurial
Network
Published Mar 13, 2018