Apache Subversion 1.10.0 Release Notes

Arbitrary code execution on clients through malicious svn+ssh URLs in svn:externals

Apache Subversion is unable to store SHA1 collisions