pip
The Python package installer
Activity
- Latest release
- 1mo ago
- Total releases
- 159
- Cadence
- ~21 days
- Last 12 months
- 8
Reach
- Stars
- 10.3k
Details
- License
- MIT
- First release
- Oct 28, 2008
| Version | Released | |
|---|---|---|
26.2.1
patch
| ||
26.2
minor
| ||
26.1.2
patch
1 CVE
CVE-2026-13346
GHSA-qwm4-qh6w-59xr
PYSEC-2026-3721
Jul 29, 2026
pip would incorrectly handle doubly-encoded package URLs from indexes
Medium
Network
High
High
pip would incorrectly handle doubly-encoded package URLs from indexes allowing for files to be installed to arbitrary locations on disk even when installing wheels. This vulnerability requires downloading or installing a package from a malicious package index to succeed, malicious packages alone are not able to exploit this vulnerability. Note that this vulnerability only materially impacts users running Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 145 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
26.1
26.1.1
26.1.2
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.2.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
26.1.1
patch
2 CVEs
CVE-2026-13346
GHSA-qwm4-qh6w-59xr
PYSEC-2026-3721
Jul 29, 2026
pip would incorrectly handle doubly-encoded package URLs from indexes
Medium
Network
High
High
pip would incorrectly handle doubly-encoded package URLs from indexes allowing for files to be installed to arbitrary locations on disk even when installing wheels. This vulnerability requires downloading or installing a package from a malicious package index to succeed, malicious packages alone are not able to exploit this vulnerability. Note that this vulnerability only materially impacts users running Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 145 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
26.1
26.1.1
26.1.2
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.2.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-8643
GHSA-wf93-45jw-7689
PYSEC-2026-196
Jun 01, 2026
pip: Path traversal in console_scripts/gui_scripts entry point names allows installing scripts outside of target directory
Medium
Local
Low
Low
pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 144 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
26.1
26.1.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.1.2
References Updated Sep 10, 2026 · Source: OSV.dev | ||
26.1
minor
2 CVEs
CVE-2026-13346
GHSA-qwm4-qh6w-59xr
PYSEC-2026-3721
Jul 29, 2026
pip would incorrectly handle doubly-encoded package URLs from indexes
Medium
Network
High
High
pip would incorrectly handle doubly-encoded package URLs from indexes allowing for files to be installed to arbitrary locations on disk even when installing wheels. This vulnerability requires downloading or installing a package from a malicious package index to succeed, malicious packages alone are not able to exploit this vulnerability. Note that this vulnerability only materially impacts users running Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 145 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
26.1
26.1.1
26.1.2
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.2.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-8643
GHSA-wf93-45jw-7689
PYSEC-2026-196
Jun 01, 2026
pip: Path traversal in console_scripts/gui_scripts entry point names allows installing scripts outside of target directory
Medium
Local
Low
Low
pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 144 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
26.1
26.1.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.1.2
References Updated Sep 10, 2026 · Source: OSV.dev | ||
26.0.1
patch
4 CVEs
CVE-2026-13346
GHSA-qwm4-qh6w-59xr
PYSEC-2026-3721
Jul 29, 2026
pip would incorrectly handle doubly-encoded package URLs from indexes
Medium
Network
High
High
pip would incorrectly handle doubly-encoded package URLs from indexes allowing for files to be installed to arbitrary locations on disk even when installing wheels. This vulnerability requires downloading or installing a package from a malicious package index to succeed, malicious packages alone are not able to exploit this vulnerability. Note that this vulnerability only materially impacts users running Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 145 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
26.1
26.1.1
26.1.2
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.2.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-6357
PYSEC-2026-2876
GHSA-jp4c-xjxw-mgf9
Jul 13, 2026
pip Vulnerable to Inclusion of Functionality from Untrusted Control Sphere
Critical
Local
Low
High
pip prior to version 26.1 would run self-update check functionality after installing wheel files which required importing well-known Python modules names. These module imports were intentionally deferred to increase startup time of the pip CLI. The patch changes self-update functionality to run before wheels are installed to prevent newly-installed modules from being imported shortly after the installation of a wheel package. Users should still review package contents prior to installation. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 142 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-3219
PYSEC-2026-2875
GHSA-58qw-9mgm-455v
Jul 13, 2026
pip has an interpretation conflict due to handling both concatenated tar and ZIP files as ZIP files
Medium
Local
Low
None
pip handles concatenated tar and ZIP files as ZIP files regardless of filename or whether a file is both a tar and ZIP file. This behavior could result in confusing installation behavior, such as installing "incorrect" files according to the filename of the archive. New behavior only proceeds with installation if the file identifies uniquely as a ZIP or tar archive, not as both. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 142 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-8643
GHSA-wf93-45jw-7689
PYSEC-2026-196
Jun 01, 2026
pip: Path traversal in console_scripts/gui_scripts entry point names allows installing scripts outside of target directory
Medium
Local
Low
Low
pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 144 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
26.1
26.1.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.1.2
References Updated Sep 10, 2026 · Source: OSV.dev | ||
26.0
major
4 CVEs
CVE-2026-13346
GHSA-qwm4-qh6w-59xr
PYSEC-2026-3721
Jul 29, 2026
pip would incorrectly handle doubly-encoded package URLs from indexes
Medium
Network
High
High
pip would incorrectly handle doubly-encoded package URLs from indexes allowing for files to be installed to arbitrary locations on disk even when installing wheels. This vulnerability requires downloading or installing a package from a malicious package index to succeed, malicious packages alone are not able to exploit this vulnerability. Note that this vulnerability only materially impacts users running Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 145 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
26.1
26.1.1
26.1.2
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.2.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-6357
PYSEC-2026-2876
GHSA-jp4c-xjxw-mgf9
Jul 13, 2026
pip Vulnerable to Inclusion of Functionality from Untrusted Control Sphere
Critical
Local
Low
High
pip prior to version 26.1 would run self-update check functionality after installing wheel files which required importing well-known Python modules names. These module imports were intentionally deferred to increase startup time of the pip CLI. The patch changes self-update functionality to run before wheels are installed to prevent newly-installed modules from being imported shortly after the installation of a wheel package. Users should still review package contents prior to installation. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 142 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-3219
PYSEC-2026-2875
GHSA-58qw-9mgm-455v
Jul 13, 2026
pip has an interpretation conflict due to handling both concatenated tar and ZIP files as ZIP files
Medium
Local
Low
None
pip handles concatenated tar and ZIP files as ZIP files regardless of filename or whether a file is both a tar and ZIP file. This behavior could result in confusing installation behavior, such as installing "incorrect" files according to the filename of the archive. New behavior only proceeds with installation if the file identifies uniquely as a ZIP or tar archive, not as both. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 142 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-8643
GHSA-wf93-45jw-7689
PYSEC-2026-196
Jun 01, 2026
pip: Path traversal in console_scripts/gui_scripts entry point names allows installing scripts outside of target directory
Medium
Local
Low
Low
pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 144 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
26.1
26.1.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.1.2
References Updated Sep 10, 2026 · Source: OSV.dev | ||
25.3
minor
5 CVEs
CVE-2026-13346
GHSA-qwm4-qh6w-59xr
PYSEC-2026-3721
Jul 29, 2026
pip would incorrectly handle doubly-encoded package URLs from indexes
Medium
Network
High
High
pip would incorrectly handle doubly-encoded package URLs from indexes allowing for files to be installed to arbitrary locations on disk even when installing wheels. This vulnerability requires downloading or installing a package from a malicious package index to succeed, malicious packages alone are not able to exploit this vulnerability. Note that this vulnerability only materially impacts users running Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 145 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
26.1
26.1.1
26.1.2
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.2.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-6357
PYSEC-2026-2876
GHSA-jp4c-xjxw-mgf9
Jul 13, 2026
pip Vulnerable to Inclusion of Functionality from Untrusted Control Sphere
Critical
Local
Low
High
pip prior to version 26.1 would run self-update check functionality after installing wheel files which required importing well-known Python modules names. These module imports were intentionally deferred to increase startup time of the pip CLI. The patch changes self-update functionality to run before wheels are installed to prevent newly-installed modules from being imported shortly after the installation of a wheel package. Users should still review package contents prior to installation. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 142 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-3219
PYSEC-2026-2875
GHSA-58qw-9mgm-455v
Jul 13, 2026
pip has an interpretation conflict due to handling both concatenated tar and ZIP files as ZIP files
Medium
Local
Low
None
pip handles concatenated tar and ZIP files as ZIP files regardless of filename or whether a file is both a tar and ZIP file. This behavior could result in confusing installation behavior, such as installing "incorrect" files according to the filename of the archive. New behavior only proceeds with installation if the file identifies uniquely as a ZIP or tar archive, not as both. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 142 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-1703
PYSEC-2026-1796
GHSA-6vgw-5pg2-w6jp
Jul 07, 2026
pip Path Traversal vulnerability
Medium
Network
Low
Low
When pip is installing and extracting a maliciously crafted wheel archive, files may be extracted outside the installation directory. The path traversal is limited to prefixes of the installation directory, thus isn't able to inject or overwrite executable files in typical situations. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 140 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-8643
GHSA-wf93-45jw-7689
PYSEC-2026-196
Jun 01, 2026
pip: Path traversal in console_scripts/gui_scripts entry point names allows installing scripts outside of target directory
Medium
Local
Low
Low
pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 144 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
26.1
26.1.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.1.2
References Updated Sep 10, 2026 · Source: OSV.dev | ||
25.2
minor
6 CVEs
CVE-2026-13346
GHSA-qwm4-qh6w-59xr
PYSEC-2026-3721
Jul 29, 2026
pip would incorrectly handle doubly-encoded package URLs from indexes
Medium
Network
High
High
pip would incorrectly handle doubly-encoded package URLs from indexes allowing for files to be installed to arbitrary locations on disk even when installing wheels. This vulnerability requires downloading or installing a package from a malicious package index to succeed, malicious packages alone are not able to exploit this vulnerability. Note that this vulnerability only materially impacts users running Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 145 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
26.1
26.1.1
26.1.2
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.2.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-6357
PYSEC-2026-2876
GHSA-jp4c-xjxw-mgf9
Jul 13, 2026
pip Vulnerable to Inclusion of Functionality from Untrusted Control Sphere
Critical
Local
Low
High
pip prior to version 26.1 would run self-update check functionality after installing wheel files which required importing well-known Python modules names. These module imports were intentionally deferred to increase startup time of the pip CLI. The patch changes self-update functionality to run before wheels are installed to prevent newly-installed modules from being imported shortly after the installation of a wheel package. Users should still review package contents prior to installation. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 142 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-3219
PYSEC-2026-2875
GHSA-58qw-9mgm-455v
Jul 13, 2026
pip has an interpretation conflict due to handling both concatenated tar and ZIP files as ZIP files
Medium
Local
Low
None
pip handles concatenated tar and ZIP files as ZIP files regardless of filename or whether a file is both a tar and ZIP file. This behavior could result in confusing installation behavior, such as installing "incorrect" files according to the filename of the archive. New behavior only proceeds with installation if the file identifies uniquely as a ZIP or tar archive, not as both. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 142 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-1703
PYSEC-2026-1796
GHSA-6vgw-5pg2-w6jp
Jul 07, 2026
pip Path Traversal vulnerability
Medium
Network
Low
Low
When pip is installing and extracting a maliciously crafted wheel archive, files may be extracted outside the installation directory. The path traversal is limited to prefixes of the installation directory, thus isn't able to inject or overwrite executable files in typical situations. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 140 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-8869
PYSEC-2026-1795
GHSA-4xh5-x5gv-qwph
Jul 07, 2026
pip's fallback tar extraction doesn't check symbolic links point to extraction directory
High
Network
Low
None
When extracting a tar archive pip may not check symbolic links point into the extraction directory if the tarfile module doesn't implement PEP 706. Note that upgrading pip to a "fixed" version for this vulnerability doesn't fix all known vulnerabilities that are remediated by using a Python version that implements PEP 706. Note that this is a vulnerability in pip's fallback implementation of tar extraction for Python versions that don't implement PEP 706 and therefore are not secure to all vulnerabilities in the Python 'tarfile' module. If you're using a Python version that implements PEP 706 then pip doesn't use the "vulnerable" fallback code. Mitigations include upgrading to a version of pip that includes the fix, upgrading to a Python version that implements PEP 706 (Python >=3.9.17, >=3.10.12, >=3.11.4, or >=3.12), applying the linked patch, or inspecting source distributions (sdists) before installation as is already a best-practice. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 139 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
25.3
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-8643
GHSA-wf93-45jw-7689
PYSEC-2026-196
Jun 01, 2026
pip: Path traversal in console_scripts/gui_scripts entry point names allows installing scripts outside of target directory
Medium
Local
Low
Low
pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 144 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
26.1
26.1.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.1.2
References Updated Sep 10, 2026 · Source: OSV.dev | ||
25.1.1
patch
6 CVEs
CVE-2026-13346
GHSA-qwm4-qh6w-59xr
PYSEC-2026-3721
Jul 29, 2026
pip would incorrectly handle doubly-encoded package URLs from indexes
Medium
Network
High
High
pip would incorrectly handle doubly-encoded package URLs from indexes allowing for files to be installed to arbitrary locations on disk even when installing wheels. This vulnerability requires downloading or installing a package from a malicious package index to succeed, malicious packages alone are not able to exploit this vulnerability. Note that this vulnerability only materially impacts users running Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 145 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
26.1
26.1.1
26.1.2
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.2.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-6357
PYSEC-2026-2876
GHSA-jp4c-xjxw-mgf9
Jul 13, 2026
pip Vulnerable to Inclusion of Functionality from Untrusted Control Sphere
Critical
Local
Low
High
pip prior to version 26.1 would run self-update check functionality after installing wheel files which required importing well-known Python modules names. These module imports were intentionally deferred to increase startup time of the pip CLI. The patch changes self-update functionality to run before wheels are installed to prevent newly-installed modules from being imported shortly after the installation of a wheel package. Users should still review package contents prior to installation. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 142 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-3219
PYSEC-2026-2875
GHSA-58qw-9mgm-455v
Jul 13, 2026
pip has an interpretation conflict due to handling both concatenated tar and ZIP files as ZIP files
Medium
Local
Low
None
pip handles concatenated tar and ZIP files as ZIP files regardless of filename or whether a file is both a tar and ZIP file. This behavior could result in confusing installation behavior, such as installing "incorrect" files according to the filename of the archive. New behavior only proceeds with installation if the file identifies uniquely as a ZIP or tar archive, not as both. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 142 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-1703
PYSEC-2026-1796
GHSA-6vgw-5pg2-w6jp
Jul 07, 2026
pip Path Traversal vulnerability
Medium
Network
Low
Low
When pip is installing and extracting a maliciously crafted wheel archive, files may be extracted outside the installation directory. The path traversal is limited to prefixes of the installation directory, thus isn't able to inject or overwrite executable files in typical situations. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 140 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-8869
PYSEC-2026-1795
GHSA-4xh5-x5gv-qwph
Jul 07, 2026
pip's fallback tar extraction doesn't check symbolic links point to extraction directory
High
Network
Low
None
When extracting a tar archive pip may not check symbolic links point into the extraction directory if the tarfile module doesn't implement PEP 706. Note that upgrading pip to a "fixed" version for this vulnerability doesn't fix all known vulnerabilities that are remediated by using a Python version that implements PEP 706. Note that this is a vulnerability in pip's fallback implementation of tar extraction for Python versions that don't implement PEP 706 and therefore are not secure to all vulnerabilities in the Python 'tarfile' module. If you're using a Python version that implements PEP 706 then pip doesn't use the "vulnerable" fallback code. Mitigations include upgrading to a version of pip that includes the fix, upgrading to a Python version that implements PEP 706 (Python >=3.9.17, >=3.10.12, >=3.11.4, or >=3.12), applying the linked patch, or inspecting source distributions (sdists) before installation as is already a best-practice. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 139 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
25.3
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-8643
GHSA-wf93-45jw-7689
PYSEC-2026-196
Jun 01, 2026
pip: Path traversal in console_scripts/gui_scripts entry point names allows installing scripts outside of target directory
Medium
Local
Low
Low
pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 144 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
26.1
26.1.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.1.2
References Updated Sep 10, 2026 · Source: OSV.dev | ||
25.1
minor
6 CVEs
CVE-2026-13346
GHSA-qwm4-qh6w-59xr
PYSEC-2026-3721
Jul 29, 2026
pip would incorrectly handle doubly-encoded package URLs from indexes
Medium
Network
High
High
pip would incorrectly handle doubly-encoded package URLs from indexes allowing for files to be installed to arbitrary locations on disk even when installing wheels. This vulnerability requires downloading or installing a package from a malicious package index to succeed, malicious packages alone are not able to exploit this vulnerability. Note that this vulnerability only materially impacts users running Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 145 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
26.1
26.1.1
26.1.2
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.2.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-6357
PYSEC-2026-2876
GHSA-jp4c-xjxw-mgf9
Jul 13, 2026
pip Vulnerable to Inclusion of Functionality from Untrusted Control Sphere
Critical
Local
Low
High
pip prior to version 26.1 would run self-update check functionality after installing wheel files which required importing well-known Python modules names. These module imports were intentionally deferred to increase startup time of the pip CLI. The patch changes self-update functionality to run before wheels are installed to prevent newly-installed modules from being imported shortly after the installation of a wheel package. Users should still review package contents prior to installation. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 142 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-3219
PYSEC-2026-2875
GHSA-58qw-9mgm-455v
Jul 13, 2026
pip has an interpretation conflict due to handling both concatenated tar and ZIP files as ZIP files
Medium
Local
Low
None
pip handles concatenated tar and ZIP files as ZIP files regardless of filename or whether a file is both a tar and ZIP file. This behavior could result in confusing installation behavior, such as installing "incorrect" files according to the filename of the archive. New behavior only proceeds with installation if the file identifies uniquely as a ZIP or tar archive, not as both. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 142 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-1703
PYSEC-2026-1796
GHSA-6vgw-5pg2-w6jp
Jul 07, 2026
pip Path Traversal vulnerability
Medium
Network
Low
Low
When pip is installing and extracting a maliciously crafted wheel archive, files may be extracted outside the installation directory. The path traversal is limited to prefixes of the installation directory, thus isn't able to inject or overwrite executable files in typical situations. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 140 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-8869
PYSEC-2026-1795
GHSA-4xh5-x5gv-qwph
Jul 07, 2026
pip's fallback tar extraction doesn't check symbolic links point to extraction directory
High
Network
Low
None
When extracting a tar archive pip may not check symbolic links point into the extraction directory if the tarfile module doesn't implement PEP 706. Note that upgrading pip to a "fixed" version for this vulnerability doesn't fix all known vulnerabilities that are remediated by using a Python version that implements PEP 706. Note that this is a vulnerability in pip's fallback implementation of tar extraction for Python versions that don't implement PEP 706 and therefore are not secure to all vulnerabilities in the Python 'tarfile' module. If you're using a Python version that implements PEP 706 then pip doesn't use the "vulnerable" fallback code. Mitigations include upgrading to a version of pip that includes the fix, upgrading to a Python version that implements PEP 706 (Python >=3.9.17, >=3.10.12, >=3.11.4, or >=3.12), applying the linked patch, or inspecting source distributions (sdists) before installation as is already a best-practice. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 139 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
25.3
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-8643
GHSA-wf93-45jw-7689
PYSEC-2026-196
Jun 01, 2026
pip: Path traversal in console_scripts/gui_scripts entry point names allows installing scripts outside of target directory
Medium
Local
Low
Low
pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 144 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
26.1
26.1.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.1.2
References Updated Sep 10, 2026 · Source: OSV.dev | ||
25.0.1
patch
6 CVEs
CVE-2026-13346
GHSA-qwm4-qh6w-59xr
PYSEC-2026-3721
Jul 29, 2026
pip would incorrectly handle doubly-encoded package URLs from indexes
Medium
Network
High
High
pip would incorrectly handle doubly-encoded package URLs from indexes allowing for files to be installed to arbitrary locations on disk even when installing wheels. This vulnerability requires downloading or installing a package from a malicious package index to succeed, malicious packages alone are not able to exploit this vulnerability. Note that this vulnerability only materially impacts users running Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 145 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
26.1
26.1.1
26.1.2
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.2.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-6357
PYSEC-2026-2876
GHSA-jp4c-xjxw-mgf9
Jul 13, 2026
pip Vulnerable to Inclusion of Functionality from Untrusted Control Sphere
Critical
Local
Low
High
pip prior to version 26.1 would run self-update check functionality after installing wheel files which required importing well-known Python modules names. These module imports were intentionally deferred to increase startup time of the pip CLI. The patch changes self-update functionality to run before wheels are installed to prevent newly-installed modules from being imported shortly after the installation of a wheel package. Users should still review package contents prior to installation. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 142 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-3219
PYSEC-2026-2875
GHSA-58qw-9mgm-455v
Jul 13, 2026
pip has an interpretation conflict due to handling both concatenated tar and ZIP files as ZIP files
Medium
Local
Low
None
pip handles concatenated tar and ZIP files as ZIP files regardless of filename or whether a file is both a tar and ZIP file. This behavior could result in confusing installation behavior, such as installing "incorrect" files according to the filename of the archive. New behavior only proceeds with installation if the file identifies uniquely as a ZIP or tar archive, not as both. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 142 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-1703
PYSEC-2026-1796
GHSA-6vgw-5pg2-w6jp
Jul 07, 2026
pip Path Traversal vulnerability
Medium
Network
Low
Low
When pip is installing and extracting a maliciously crafted wheel archive, files may be extracted outside the installation directory. The path traversal is limited to prefixes of the installation directory, thus isn't able to inject or overwrite executable files in typical situations. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 140 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-8869
PYSEC-2026-1795
GHSA-4xh5-x5gv-qwph
Jul 07, 2026
pip's fallback tar extraction doesn't check symbolic links point to extraction directory
High
Network
Low
None
When extracting a tar archive pip may not check symbolic links point into the extraction directory if the tarfile module doesn't implement PEP 706. Note that upgrading pip to a "fixed" version for this vulnerability doesn't fix all known vulnerabilities that are remediated by using a Python version that implements PEP 706. Note that this is a vulnerability in pip's fallback implementation of tar extraction for Python versions that don't implement PEP 706 and therefore are not secure to all vulnerabilities in the Python 'tarfile' module. If you're using a Python version that implements PEP 706 then pip doesn't use the "vulnerable" fallback code. Mitigations include upgrading to a version of pip that includes the fix, upgrading to a Python version that implements PEP 706 (Python >=3.9.17, >=3.10.12, >=3.11.4, or >=3.12), applying the linked patch, or inspecting source distributions (sdists) before installation as is already a best-practice. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 139 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
25.3
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-8643
GHSA-wf93-45jw-7689
PYSEC-2026-196
Jun 01, 2026
pip: Path traversal in console_scripts/gui_scripts entry point names allows installing scripts outside of target directory
Medium
Local
Low
Low
pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 144 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
26.1
26.1.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.1.2
References Updated Sep 10, 2026 · Source: OSV.dev | ||
25.0
major
6 CVEs
CVE-2026-13346
GHSA-qwm4-qh6w-59xr
PYSEC-2026-3721
Jul 29, 2026
pip would incorrectly handle doubly-encoded package URLs from indexes
Medium
Network
High
High
pip would incorrectly handle doubly-encoded package URLs from indexes allowing for files to be installed to arbitrary locations on disk even when installing wheels. This vulnerability requires downloading or installing a package from a malicious package index to succeed, malicious packages alone are not able to exploit this vulnerability. Note that this vulnerability only materially impacts users running Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 145 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
26.1
26.1.1
26.1.2
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.2.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-6357
PYSEC-2026-2876
GHSA-jp4c-xjxw-mgf9
Jul 13, 2026
pip Vulnerable to Inclusion of Functionality from Untrusted Control Sphere
Critical
Local
Low
High
pip prior to version 26.1 would run self-update check functionality after installing wheel files which required importing well-known Python modules names. These module imports were intentionally deferred to increase startup time of the pip CLI. The patch changes self-update functionality to run before wheels are installed to prevent newly-installed modules from being imported shortly after the installation of a wheel package. Users should still review package contents prior to installation. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 142 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-3219
PYSEC-2026-2875
GHSA-58qw-9mgm-455v
Jul 13, 2026
pip has an interpretation conflict due to handling both concatenated tar and ZIP files as ZIP files
Medium
Local
Low
None
pip handles concatenated tar and ZIP files as ZIP files regardless of filename or whether a file is both a tar and ZIP file. This behavior could result in confusing installation behavior, such as installing "incorrect" files according to the filename of the archive. New behavior only proceeds with installation if the file identifies uniquely as a ZIP or tar archive, not as both. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 142 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-1703
PYSEC-2026-1796
GHSA-6vgw-5pg2-w6jp
Jul 07, 2026
pip Path Traversal vulnerability
Medium
Network
Low
Low
When pip is installing and extracting a maliciously crafted wheel archive, files may be extracted outside the installation directory. The path traversal is limited to prefixes of the installation directory, thus isn't able to inject or overwrite executable files in typical situations. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 140 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-8869
PYSEC-2026-1795
GHSA-4xh5-x5gv-qwph
Jul 07, 2026
pip's fallback tar extraction doesn't check symbolic links point to extraction directory
High
Network
Low
None
When extracting a tar archive pip may not check symbolic links point into the extraction directory if the tarfile module doesn't implement PEP 706. Note that upgrading pip to a "fixed" version for this vulnerability doesn't fix all known vulnerabilities that are remediated by using a Python version that implements PEP 706. Note that this is a vulnerability in pip's fallback implementation of tar extraction for Python versions that don't implement PEP 706 and therefore are not secure to all vulnerabilities in the Python 'tarfile' module. If you're using a Python version that implements PEP 706 then pip doesn't use the "vulnerable" fallback code. Mitigations include upgrading to a version of pip that includes the fix, upgrading to a Python version that implements PEP 706 (Python >=3.9.17, >=3.10.12, >=3.11.4, or >=3.12), applying the linked patch, or inspecting source distributions (sdists) before installation as is already a best-practice. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 139 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
25.3
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-8643
GHSA-wf93-45jw-7689
PYSEC-2026-196
Jun 01, 2026
pip: Path traversal in console_scripts/gui_scripts entry point names allows installing scripts outside of target directory
Medium
Local
Low
Low
pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 144 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
26.1
26.1.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.1.2
References Updated Sep 10, 2026 · Source: OSV.dev | ||
24.3.1
patch
6 CVEs
CVE-2026-13346
GHSA-qwm4-qh6w-59xr
PYSEC-2026-3721
Jul 29, 2026
pip would incorrectly handle doubly-encoded package URLs from indexes
Medium
Network
High
High
pip would incorrectly handle doubly-encoded package URLs from indexes allowing for files to be installed to arbitrary locations on disk even when installing wheels. This vulnerability requires downloading or installing a package from a malicious package index to succeed, malicious packages alone are not able to exploit this vulnerability. Note that this vulnerability only materially impacts users running Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 145 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
26.1
26.1.1
26.1.2
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.2.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-6357
PYSEC-2026-2876
GHSA-jp4c-xjxw-mgf9
Jul 13, 2026
pip Vulnerable to Inclusion of Functionality from Untrusted Control Sphere
Critical
Local
Low
High
pip prior to version 26.1 would run self-update check functionality after installing wheel files which required importing well-known Python modules names. These module imports were intentionally deferred to increase startup time of the pip CLI. The patch changes self-update functionality to run before wheels are installed to prevent newly-installed modules from being imported shortly after the installation of a wheel package. Users should still review package contents prior to installation. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 142 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-3219
PYSEC-2026-2875
GHSA-58qw-9mgm-455v
Jul 13, 2026
pip has an interpretation conflict due to handling both concatenated tar and ZIP files as ZIP files
Medium
Local
Low
None
pip handles concatenated tar and ZIP files as ZIP files regardless of filename or whether a file is both a tar and ZIP file. This behavior could result in confusing installation behavior, such as installing "incorrect" files according to the filename of the archive. New behavior only proceeds with installation if the file identifies uniquely as a ZIP or tar archive, not as both. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 142 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-1703
PYSEC-2026-1796
GHSA-6vgw-5pg2-w6jp
Jul 07, 2026
pip Path Traversal vulnerability
Medium
Network
Low
Low
When pip is installing and extracting a maliciously crafted wheel archive, files may be extracted outside the installation directory. The path traversal is limited to prefixes of the installation directory, thus isn't able to inject or overwrite executable files in typical situations. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 140 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-8869
PYSEC-2026-1795
GHSA-4xh5-x5gv-qwph
Jul 07, 2026
pip's fallback tar extraction doesn't check symbolic links point to extraction directory
High
Network
Low
None
When extracting a tar archive pip may not check symbolic links point into the extraction directory if the tarfile module doesn't implement PEP 706. Note that upgrading pip to a "fixed" version for this vulnerability doesn't fix all known vulnerabilities that are remediated by using a Python version that implements PEP 706. Note that this is a vulnerability in pip's fallback implementation of tar extraction for Python versions that don't implement PEP 706 and therefore are not secure to all vulnerabilities in the Python 'tarfile' module. If you're using a Python version that implements PEP 706 then pip doesn't use the "vulnerable" fallback code. Mitigations include upgrading to a version of pip that includes the fix, upgrading to a Python version that implements PEP 706 (Python >=3.9.17, >=3.10.12, >=3.11.4, or >=3.12), applying the linked patch, or inspecting source distributions (sdists) before installation as is already a best-practice. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 139 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
25.3
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-8643
GHSA-wf93-45jw-7689
PYSEC-2026-196
Jun 01, 2026
pip: Path traversal in console_scripts/gui_scripts entry point names allows installing scripts outside of target directory
Medium
Local
Low
Low
pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 144 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
26.1
26.1.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.1.2
References Updated Sep 10, 2026 · Source: OSV.dev | ||
24.3
minor
6 CVEs
CVE-2026-13346
GHSA-qwm4-qh6w-59xr
PYSEC-2026-3721
Jul 29, 2026
pip would incorrectly handle doubly-encoded package URLs from indexes
Medium
Network
High
High
pip would incorrectly handle doubly-encoded package URLs from indexes allowing for files to be installed to arbitrary locations on disk even when installing wheels. This vulnerability requires downloading or installing a package from a malicious package index to succeed, malicious packages alone are not able to exploit this vulnerability. Note that this vulnerability only materially impacts users running Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 145 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
26.1
26.1.1
26.1.2
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.2.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-6357
PYSEC-2026-2876
GHSA-jp4c-xjxw-mgf9
Jul 13, 2026
pip Vulnerable to Inclusion of Functionality from Untrusted Control Sphere
Critical
Local
Low
High
pip prior to version 26.1 would run self-update check functionality after installing wheel files which required importing well-known Python modules names. These module imports were intentionally deferred to increase startup time of the pip CLI. The patch changes self-update functionality to run before wheels are installed to prevent newly-installed modules from being imported shortly after the installation of a wheel package. Users should still review package contents prior to installation. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 142 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-3219
PYSEC-2026-2875
GHSA-58qw-9mgm-455v
Jul 13, 2026
pip has an interpretation conflict due to handling both concatenated tar and ZIP files as ZIP files
Medium
Local
Low
None
pip handles concatenated tar and ZIP files as ZIP files regardless of filename or whether a file is both a tar and ZIP file. This behavior could result in confusing installation behavior, such as installing "incorrect" files according to the filename of the archive. New behavior only proceeds with installation if the file identifies uniquely as a ZIP or tar archive, not as both. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 142 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-1703
PYSEC-2026-1796
GHSA-6vgw-5pg2-w6jp
Jul 07, 2026
pip Path Traversal vulnerability
Medium
Network
Low
Low
When pip is installing and extracting a maliciously crafted wheel archive, files may be extracted outside the installation directory. The path traversal is limited to prefixes of the installation directory, thus isn't able to inject or overwrite executable files in typical situations. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 140 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-8869
PYSEC-2026-1795
GHSA-4xh5-x5gv-qwph
Jul 07, 2026
pip's fallback tar extraction doesn't check symbolic links point to extraction directory
High
Network
Low
None
When extracting a tar archive pip may not check symbolic links point into the extraction directory if the tarfile module doesn't implement PEP 706. Note that upgrading pip to a "fixed" version for this vulnerability doesn't fix all known vulnerabilities that are remediated by using a Python version that implements PEP 706. Note that this is a vulnerability in pip's fallback implementation of tar extraction for Python versions that don't implement PEP 706 and therefore are not secure to all vulnerabilities in the Python 'tarfile' module. If you're using a Python version that implements PEP 706 then pip doesn't use the "vulnerable" fallback code. Mitigations include upgrading to a version of pip that includes the fix, upgrading to a Python version that implements PEP 706 (Python >=3.9.17, >=3.10.12, >=3.11.4, or >=3.12), applying the linked patch, or inspecting source distributions (sdists) before installation as is already a best-practice. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 139 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
25.3
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-8643
GHSA-wf93-45jw-7689
PYSEC-2026-196
Jun 01, 2026
pip: Path traversal in console_scripts/gui_scripts entry point names allows installing scripts outside of target directory
Medium
Local
Low
Low
pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 144 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
26.1
26.1.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.1.2
References Updated Sep 10, 2026 · Source: OSV.dev | ||
24.2
minor
6 CVEs
CVE-2026-13346
GHSA-qwm4-qh6w-59xr
PYSEC-2026-3721
Jul 29, 2026
pip would incorrectly handle doubly-encoded package URLs from indexes
Medium
Network
High
High
pip would incorrectly handle doubly-encoded package URLs from indexes allowing for files to be installed to arbitrary locations on disk even when installing wheels. This vulnerability requires downloading or installing a package from a malicious package index to succeed, malicious packages alone are not able to exploit this vulnerability. Note that this vulnerability only materially impacts users running Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 145 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
26.1
26.1.1
26.1.2
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.2.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-6357
PYSEC-2026-2876
GHSA-jp4c-xjxw-mgf9
Jul 13, 2026
pip Vulnerable to Inclusion of Functionality from Untrusted Control Sphere
Critical
Local
Low
High
pip prior to version 26.1 would run self-update check functionality after installing wheel files which required importing well-known Python modules names. These module imports were intentionally deferred to increase startup time of the pip CLI. The patch changes self-update functionality to run before wheels are installed to prevent newly-installed modules from being imported shortly after the installation of a wheel package. Users should still review package contents prior to installation. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 142 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-3219
PYSEC-2026-2875
GHSA-58qw-9mgm-455v
Jul 13, 2026
pip has an interpretation conflict due to handling both concatenated tar and ZIP files as ZIP files
Medium
Local
Low
None
pip handles concatenated tar and ZIP files as ZIP files regardless of filename or whether a file is both a tar and ZIP file. This behavior could result in confusing installation behavior, such as installing "incorrect" files according to the filename of the archive. New behavior only proceeds with installation if the file identifies uniquely as a ZIP or tar archive, not as both. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 142 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-1703
PYSEC-2026-1796
GHSA-6vgw-5pg2-w6jp
Jul 07, 2026
pip Path Traversal vulnerability
Medium
Network
Low
Low
When pip is installing and extracting a maliciously crafted wheel archive, files may be extracted outside the installation directory. The path traversal is limited to prefixes of the installation directory, thus isn't able to inject or overwrite executable files in typical situations. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 140 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-8869
PYSEC-2026-1795
GHSA-4xh5-x5gv-qwph
Jul 07, 2026
pip's fallback tar extraction doesn't check symbolic links point to extraction directory
High
Network
Low
None
When extracting a tar archive pip may not check symbolic links point into the extraction directory if the tarfile module doesn't implement PEP 706. Note that upgrading pip to a "fixed" version for this vulnerability doesn't fix all known vulnerabilities that are remediated by using a Python version that implements PEP 706. Note that this is a vulnerability in pip's fallback implementation of tar extraction for Python versions that don't implement PEP 706 and therefore are not secure to all vulnerabilities in the Python 'tarfile' module. If you're using a Python version that implements PEP 706 then pip doesn't use the "vulnerable" fallback code. Mitigations include upgrading to a version of pip that includes the fix, upgrading to a Python version that implements PEP 706 (Python >=3.9.17, >=3.10.12, >=3.11.4, or >=3.12), applying the linked patch, or inspecting source distributions (sdists) before installation as is already a best-practice. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 139 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
25.3
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-8643
GHSA-wf93-45jw-7689
PYSEC-2026-196
Jun 01, 2026
pip: Path traversal in console_scripts/gui_scripts entry point names allows installing scripts outside of target directory
Medium
Local
Low
Low
pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 144 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
26.1
26.1.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.1.2
References Updated Sep 10, 2026 · Source: OSV.dev | ||
24.1.2
patch
6 CVEs
CVE-2026-13346
GHSA-qwm4-qh6w-59xr
PYSEC-2026-3721
Jul 29, 2026
pip would incorrectly handle doubly-encoded package URLs from indexes
Medium
Network
High
High
pip would incorrectly handle doubly-encoded package URLs from indexes allowing for files to be installed to arbitrary locations on disk even when installing wheels. This vulnerability requires downloading or installing a package from a malicious package index to succeed, malicious packages alone are not able to exploit this vulnerability. Note that this vulnerability only materially impacts users running Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 145 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
26.1
26.1.1
26.1.2
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.2.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-6357
PYSEC-2026-2876
GHSA-jp4c-xjxw-mgf9
Jul 13, 2026
pip Vulnerable to Inclusion of Functionality from Untrusted Control Sphere
Critical
Local
Low
High
pip prior to version 26.1 would run self-update check functionality after installing wheel files which required importing well-known Python modules names. These module imports were intentionally deferred to increase startup time of the pip CLI. The patch changes self-update functionality to run before wheels are installed to prevent newly-installed modules from being imported shortly after the installation of a wheel package. Users should still review package contents prior to installation. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 142 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-3219
PYSEC-2026-2875
GHSA-58qw-9mgm-455v
Jul 13, 2026
pip has an interpretation conflict due to handling both concatenated tar and ZIP files as ZIP files
Medium
Local
Low
None
pip handles concatenated tar and ZIP files as ZIP files regardless of filename or whether a file is both a tar and ZIP file. This behavior could result in confusing installation behavior, such as installing "incorrect" files according to the filename of the archive. New behavior only proceeds with installation if the file identifies uniquely as a ZIP or tar archive, not as both. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 142 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-1703
PYSEC-2026-1796
GHSA-6vgw-5pg2-w6jp
Jul 07, 2026
pip Path Traversal vulnerability
Medium
Network
Low
Low
When pip is installing and extracting a maliciously crafted wheel archive, files may be extracted outside the installation directory. The path traversal is limited to prefixes of the installation directory, thus isn't able to inject or overwrite executable files in typical situations. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 140 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-8869
PYSEC-2026-1795
GHSA-4xh5-x5gv-qwph
Jul 07, 2026
pip's fallback tar extraction doesn't check symbolic links point to extraction directory
High
Network
Low
None
When extracting a tar archive pip may not check symbolic links point into the extraction directory if the tarfile module doesn't implement PEP 706. Note that upgrading pip to a "fixed" version for this vulnerability doesn't fix all known vulnerabilities that are remediated by using a Python version that implements PEP 706. Note that this is a vulnerability in pip's fallback implementation of tar extraction for Python versions that don't implement PEP 706 and therefore are not secure to all vulnerabilities in the Python 'tarfile' module. If you're using a Python version that implements PEP 706 then pip doesn't use the "vulnerable" fallback code. Mitigations include upgrading to a version of pip that includes the fix, upgrading to a Python version that implements PEP 706 (Python >=3.9.17, >=3.10.12, >=3.11.4, or >=3.12), applying the linked patch, or inspecting source distributions (sdists) before installation as is already a best-practice. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 139 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
25.3
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-8643
GHSA-wf93-45jw-7689
PYSEC-2026-196
Jun 01, 2026
pip: Path traversal in console_scripts/gui_scripts entry point names allows installing scripts outside of target directory
Medium
Local
Low
Low
pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 144 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
26.1
26.1.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.1.2
References Updated Sep 10, 2026 · Source: OSV.dev | ||
24.1.1
patch
6 CVEs
CVE-2026-13346
GHSA-qwm4-qh6w-59xr
PYSEC-2026-3721
Jul 29, 2026
pip would incorrectly handle doubly-encoded package URLs from indexes
Medium
Network
High
High
pip would incorrectly handle doubly-encoded package URLs from indexes allowing for files to be installed to arbitrary locations on disk even when installing wheels. This vulnerability requires downloading or installing a package from a malicious package index to succeed, malicious packages alone are not able to exploit this vulnerability. Note that this vulnerability only materially impacts users running Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 145 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
26.1
26.1.1
26.1.2
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.2.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-6357
PYSEC-2026-2876
GHSA-jp4c-xjxw-mgf9
Jul 13, 2026
pip Vulnerable to Inclusion of Functionality from Untrusted Control Sphere
Critical
Local
Low
High
pip prior to version 26.1 would run self-update check functionality after installing wheel files which required importing well-known Python modules names. These module imports were intentionally deferred to increase startup time of the pip CLI. The patch changes self-update functionality to run before wheels are installed to prevent newly-installed modules from being imported shortly after the installation of a wheel package. Users should still review package contents prior to installation. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 142 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-3219
PYSEC-2026-2875
GHSA-58qw-9mgm-455v
Jul 13, 2026
pip has an interpretation conflict due to handling both concatenated tar and ZIP files as ZIP files
Medium
Local
Low
None
pip handles concatenated tar and ZIP files as ZIP files regardless of filename or whether a file is both a tar and ZIP file. This behavior could result in confusing installation behavior, such as installing "incorrect" files according to the filename of the archive. New behavior only proceeds with installation if the file identifies uniquely as a ZIP or tar archive, not as both. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 142 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-1703
PYSEC-2026-1796
GHSA-6vgw-5pg2-w6jp
Jul 07, 2026
pip Path Traversal vulnerability
Medium
Network
Low
Low
When pip is installing and extracting a maliciously crafted wheel archive, files may be extracted outside the installation directory. The path traversal is limited to prefixes of the installation directory, thus isn't able to inject or overwrite executable files in typical situations. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 140 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-8869
PYSEC-2026-1795
GHSA-4xh5-x5gv-qwph
Jul 07, 2026
pip's fallback tar extraction doesn't check symbolic links point to extraction directory
High
Network
Low
None
When extracting a tar archive pip may not check symbolic links point into the extraction directory if the tarfile module doesn't implement PEP 706. Note that upgrading pip to a "fixed" version for this vulnerability doesn't fix all known vulnerabilities that are remediated by using a Python version that implements PEP 706. Note that this is a vulnerability in pip's fallback implementation of tar extraction for Python versions that don't implement PEP 706 and therefore are not secure to all vulnerabilities in the Python 'tarfile' module. If you're using a Python version that implements PEP 706 then pip doesn't use the "vulnerable" fallback code. Mitigations include upgrading to a version of pip that includes the fix, upgrading to a Python version that implements PEP 706 (Python >=3.9.17, >=3.10.12, >=3.11.4, or >=3.12), applying the linked patch, or inspecting source distributions (sdists) before installation as is already a best-practice. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 139 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
25.3
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-8643
GHSA-wf93-45jw-7689
PYSEC-2026-196
Jun 01, 2026
pip: Path traversal in console_scripts/gui_scripts entry point names allows installing scripts outside of target directory
Medium
Local
Low
Low
pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 144 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
26.1
26.1.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.1.2
References Updated Sep 10, 2026 · Source: OSV.dev | ||
24.1
minor
6 CVEs
CVE-2026-13346
GHSA-qwm4-qh6w-59xr
PYSEC-2026-3721
Jul 29, 2026
pip would incorrectly handle doubly-encoded package URLs from indexes
Medium
Network
High
High
pip would incorrectly handle doubly-encoded package URLs from indexes allowing for files to be installed to arbitrary locations on disk even when installing wheels. This vulnerability requires downloading or installing a package from a malicious package index to succeed, malicious packages alone are not able to exploit this vulnerability. Note that this vulnerability only materially impacts users running Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 145 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
26.1
26.1.1
26.1.2
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.2.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-6357
PYSEC-2026-2876
GHSA-jp4c-xjxw-mgf9
Jul 13, 2026
pip Vulnerable to Inclusion of Functionality from Untrusted Control Sphere
Critical
Local
Low
High
pip prior to version 26.1 would run self-update check functionality after installing wheel files which required importing well-known Python modules names. These module imports were intentionally deferred to increase startup time of the pip CLI. The patch changes self-update functionality to run before wheels are installed to prevent newly-installed modules from being imported shortly after the installation of a wheel package. Users should still review package contents prior to installation. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 142 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-3219
PYSEC-2026-2875
GHSA-58qw-9mgm-455v
Jul 13, 2026
pip has an interpretation conflict due to handling both concatenated tar and ZIP files as ZIP files
Medium
Local
Low
None
pip handles concatenated tar and ZIP files as ZIP files regardless of filename or whether a file is both a tar and ZIP file. This behavior could result in confusing installation behavior, such as installing "incorrect" files according to the filename of the archive. New behavior only proceeds with installation if the file identifies uniquely as a ZIP or tar archive, not as both. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 142 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-1703
PYSEC-2026-1796
GHSA-6vgw-5pg2-w6jp
Jul 07, 2026
pip Path Traversal vulnerability
Medium
Network
Low
Low
When pip is installing and extracting a maliciously crafted wheel archive, files may be extracted outside the installation directory. The path traversal is limited to prefixes of the installation directory, thus isn't able to inject or overwrite executable files in typical situations. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 140 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-8869
PYSEC-2026-1795
GHSA-4xh5-x5gv-qwph
Jul 07, 2026
pip's fallback tar extraction doesn't check symbolic links point to extraction directory
High
Network
Low
None
When extracting a tar archive pip may not check symbolic links point into the extraction directory if the tarfile module doesn't implement PEP 706. Note that upgrading pip to a "fixed" version for this vulnerability doesn't fix all known vulnerabilities that are remediated by using a Python version that implements PEP 706. Note that this is a vulnerability in pip's fallback implementation of tar extraction for Python versions that don't implement PEP 706 and therefore are not secure to all vulnerabilities in the Python 'tarfile' module. If you're using a Python version that implements PEP 706 then pip doesn't use the "vulnerable" fallback code. Mitigations include upgrading to a version of pip that includes the fix, upgrading to a Python version that implements PEP 706 (Python >=3.9.17, >=3.10.12, >=3.11.4, or >=3.12), applying the linked patch, or inspecting source distributions (sdists) before installation as is already a best-practice. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 139 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
25.3
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-8643
GHSA-wf93-45jw-7689
PYSEC-2026-196
Jun 01, 2026
pip: Path traversal in console_scripts/gui_scripts entry point names allows installing scripts outside of target directory
Medium
Local
Low
Low
pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 144 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
26.1
26.1.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.1.2
References Updated Sep 10, 2026 · Source: OSV.dev | ||
24.1b2
pre
6 CVEs
CVE-2026-13346
GHSA-qwm4-qh6w-59xr
PYSEC-2026-3721
Jul 29, 2026
pip would incorrectly handle doubly-encoded package URLs from indexes
Medium
Network
High
High
pip would incorrectly handle doubly-encoded package URLs from indexes allowing for files to be installed to arbitrary locations on disk even when installing wheels. This vulnerability requires downloading or installing a package from a malicious package index to succeed, malicious packages alone are not able to exploit this vulnerability. Note that this vulnerability only materially impacts users running Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 145 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
26.1
26.1.1
26.1.2
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.2.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-6357
PYSEC-2026-2876
GHSA-jp4c-xjxw-mgf9
Jul 13, 2026
pip Vulnerable to Inclusion of Functionality from Untrusted Control Sphere
Critical
Local
Low
High
pip prior to version 26.1 would run self-update check functionality after installing wheel files which required importing well-known Python modules names. These module imports were intentionally deferred to increase startup time of the pip CLI. The patch changes self-update functionality to run before wheels are installed to prevent newly-installed modules from being imported shortly after the installation of a wheel package. Users should still review package contents prior to installation. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 142 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-3219
PYSEC-2026-2875
GHSA-58qw-9mgm-455v
Jul 13, 2026
pip has an interpretation conflict due to handling both concatenated tar and ZIP files as ZIP files
Medium
Local
Low
None
pip handles concatenated tar and ZIP files as ZIP files regardless of filename or whether a file is both a tar and ZIP file. This behavior could result in confusing installation behavior, such as installing "incorrect" files according to the filename of the archive. New behavior only proceeds with installation if the file identifies uniquely as a ZIP or tar archive, not as both. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 142 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-1703
PYSEC-2026-1796
GHSA-6vgw-5pg2-w6jp
Jul 07, 2026
pip Path Traversal vulnerability
Medium
Network
Low
Low
When pip is installing and extracting a maliciously crafted wheel archive, files may be extracted outside the installation directory. The path traversal is limited to prefixes of the installation directory, thus isn't able to inject or overwrite executable files in typical situations. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 140 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-8869
PYSEC-2026-1795
GHSA-4xh5-x5gv-qwph
Jul 07, 2026
pip's fallback tar extraction doesn't check symbolic links point to extraction directory
High
Network
Low
None
When extracting a tar archive pip may not check symbolic links point into the extraction directory if the tarfile module doesn't implement PEP 706. Note that upgrading pip to a "fixed" version for this vulnerability doesn't fix all known vulnerabilities that are remediated by using a Python version that implements PEP 706. Note that this is a vulnerability in pip's fallback implementation of tar extraction for Python versions that don't implement PEP 706 and therefore are not secure to all vulnerabilities in the Python 'tarfile' module. If you're using a Python version that implements PEP 706 then pip doesn't use the "vulnerable" fallback code. Mitigations include upgrading to a version of pip that includes the fix, upgrading to a Python version that implements PEP 706 (Python >=3.9.17, >=3.10.12, >=3.11.4, or >=3.12), applying the linked patch, or inspecting source distributions (sdists) before installation as is already a best-practice. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 139 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
25.3
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-8643
GHSA-wf93-45jw-7689
PYSEC-2026-196
Jun 01, 2026
pip: Path traversal in console_scripts/gui_scripts entry point names allows installing scripts outside of target directory
Medium
Local
Low
Low
pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 144 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
26.1
26.1.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.1.2
References Updated Sep 10, 2026 · Source: OSV.dev | ||
24.1b1
pre
6 CVEs
CVE-2026-13346
GHSA-qwm4-qh6w-59xr
PYSEC-2026-3721
Jul 29, 2026
pip would incorrectly handle doubly-encoded package URLs from indexes
Medium
Network
High
High
pip would incorrectly handle doubly-encoded package URLs from indexes allowing for files to be installed to arbitrary locations on disk even when installing wheels. This vulnerability requires downloading or installing a package from a malicious package index to succeed, malicious packages alone are not able to exploit this vulnerability. Note that this vulnerability only materially impacts users running Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 145 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
26.1
26.1.1
26.1.2
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.2.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-6357
PYSEC-2026-2876
GHSA-jp4c-xjxw-mgf9
Jul 13, 2026
pip Vulnerable to Inclusion of Functionality from Untrusted Control Sphere
Critical
Local
Low
High
pip prior to version 26.1 would run self-update check functionality after installing wheel files which required importing well-known Python modules names. These module imports were intentionally deferred to increase startup time of the pip CLI. The patch changes self-update functionality to run before wheels are installed to prevent newly-installed modules from being imported shortly after the installation of a wheel package. Users should still review package contents prior to installation. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 142 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-3219
PYSEC-2026-2875
GHSA-58qw-9mgm-455v
Jul 13, 2026
pip has an interpretation conflict due to handling both concatenated tar and ZIP files as ZIP files
Medium
Local
Low
None
pip handles concatenated tar and ZIP files as ZIP files regardless of filename or whether a file is both a tar and ZIP file. This behavior could result in confusing installation behavior, such as installing "incorrect" files according to the filename of the archive. New behavior only proceeds with installation if the file identifies uniquely as a ZIP or tar archive, not as both. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 142 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-1703
PYSEC-2026-1796
GHSA-6vgw-5pg2-w6jp
Jul 07, 2026
pip Path Traversal vulnerability
Medium
Network
Low
Low
When pip is installing and extracting a maliciously crafted wheel archive, files may be extracted outside the installation directory. The path traversal is limited to prefixes of the installation directory, thus isn't able to inject or overwrite executable files in typical situations. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 140 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-8869
PYSEC-2026-1795
GHSA-4xh5-x5gv-qwph
Jul 07, 2026
pip's fallback tar extraction doesn't check symbolic links point to extraction directory
High
Network
Low
None
When extracting a tar archive pip may not check symbolic links point into the extraction directory if the tarfile module doesn't implement PEP 706. Note that upgrading pip to a "fixed" version for this vulnerability doesn't fix all known vulnerabilities that are remediated by using a Python version that implements PEP 706. Note that this is a vulnerability in pip's fallback implementation of tar extraction for Python versions that don't implement PEP 706 and therefore are not secure to all vulnerabilities in the Python 'tarfile' module. If you're using a Python version that implements PEP 706 then pip doesn't use the "vulnerable" fallback code. Mitigations include upgrading to a version of pip that includes the fix, upgrading to a Python version that implements PEP 706 (Python >=3.9.17, >=3.10.12, >=3.11.4, or >=3.12), applying the linked patch, or inspecting source distributions (sdists) before installation as is already a best-practice. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 139 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
25.3
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-8643
GHSA-wf93-45jw-7689
PYSEC-2026-196
Jun 01, 2026
pip: Path traversal in console_scripts/gui_scripts entry point names allows installing scripts outside of target directory
Medium
Local
Low
Low
pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 144 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
26.1
26.1.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.1.2
References Updated Sep 10, 2026 · Source: OSV.dev | ||
24.0
major
6 CVEs
CVE-2026-13346
GHSA-qwm4-qh6w-59xr
PYSEC-2026-3721
Jul 29, 2026
pip would incorrectly handle doubly-encoded package URLs from indexes
Medium
Network
High
High
pip would incorrectly handle doubly-encoded package URLs from indexes allowing for files to be installed to arbitrary locations on disk even when installing wheels. This vulnerability requires downloading or installing a package from a malicious package index to succeed, malicious packages alone are not able to exploit this vulnerability. Note that this vulnerability only materially impacts users running Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 145 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
26.1
26.1.1
26.1.2
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.2.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-6357
PYSEC-2026-2876
GHSA-jp4c-xjxw-mgf9
Jul 13, 2026
pip Vulnerable to Inclusion of Functionality from Untrusted Control Sphere
Critical
Local
Low
High
pip prior to version 26.1 would run self-update check functionality after installing wheel files which required importing well-known Python modules names. These module imports were intentionally deferred to increase startup time of the pip CLI. The patch changes self-update functionality to run before wheels are installed to prevent newly-installed modules from being imported shortly after the installation of a wheel package. Users should still review package contents prior to installation. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 142 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-3219
PYSEC-2026-2875
GHSA-58qw-9mgm-455v
Jul 13, 2026
pip has an interpretation conflict due to handling both concatenated tar and ZIP files as ZIP files
Medium
Local
Low
None
pip handles concatenated tar and ZIP files as ZIP files regardless of filename or whether a file is both a tar and ZIP file. This behavior could result in confusing installation behavior, such as installing "incorrect" files according to the filename of the archive. New behavior only proceeds with installation if the file identifies uniquely as a ZIP or tar archive, not as both. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 142 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-1703
PYSEC-2026-1796
GHSA-6vgw-5pg2-w6jp
Jul 07, 2026
pip Path Traversal vulnerability
Medium
Network
Low
Low
When pip is installing and extracting a maliciously crafted wheel archive, files may be extracted outside the installation directory. The path traversal is limited to prefixes of the installation directory, thus isn't able to inject or overwrite executable files in typical situations. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 140 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-8869
PYSEC-2026-1795
GHSA-4xh5-x5gv-qwph
Jul 07, 2026
pip's fallback tar extraction doesn't check symbolic links point to extraction directory
High
Network
Low
None
When extracting a tar archive pip may not check symbolic links point into the extraction directory if the tarfile module doesn't implement PEP 706. Note that upgrading pip to a "fixed" version for this vulnerability doesn't fix all known vulnerabilities that are remediated by using a Python version that implements PEP 706. Note that this is a vulnerability in pip's fallback implementation of tar extraction for Python versions that don't implement PEP 706 and therefore are not secure to all vulnerabilities in the Python 'tarfile' module. If you're using a Python version that implements PEP 706 then pip doesn't use the "vulnerable" fallback code. Mitigations include upgrading to a version of pip that includes the fix, upgrading to a Python version that implements PEP 706 (Python >=3.9.17, >=3.10.12, >=3.11.4, or >=3.12), applying the linked patch, or inspecting source distributions (sdists) before installation as is already a best-practice. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 139 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
25.3
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-8643
GHSA-wf93-45jw-7689
PYSEC-2026-196
Jun 01, 2026
pip: Path traversal in console_scripts/gui_scripts entry point names allows installing scripts outside of target directory
Medium
Local
Low
Low
pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 144 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
26.1
26.1.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.1.2
References Updated Sep 10, 2026 · Source: OSV.dev | ||
23.3.2
patch
6 CVEs
CVE-2026-13346
GHSA-qwm4-qh6w-59xr
PYSEC-2026-3721
Jul 29, 2026
pip would incorrectly handle doubly-encoded package URLs from indexes
Medium
Network
High
High
pip would incorrectly handle doubly-encoded package URLs from indexes allowing for files to be installed to arbitrary locations on disk even when installing wheels. This vulnerability requires downloading or installing a package from a malicious package index to succeed, malicious packages alone are not able to exploit this vulnerability. Note that this vulnerability only materially impacts users running Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 145 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
26.1
26.1.1
26.1.2
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.2.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-6357
PYSEC-2026-2876
GHSA-jp4c-xjxw-mgf9
Jul 13, 2026
pip Vulnerable to Inclusion of Functionality from Untrusted Control Sphere
Critical
Local
Low
High
pip prior to version 26.1 would run self-update check functionality after installing wheel files which required importing well-known Python modules names. These module imports were intentionally deferred to increase startup time of the pip CLI. The patch changes self-update functionality to run before wheels are installed to prevent newly-installed modules from being imported shortly after the installation of a wheel package. Users should still review package contents prior to installation. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 142 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-3219
PYSEC-2026-2875
GHSA-58qw-9mgm-455v
Jul 13, 2026
pip has an interpretation conflict due to handling both concatenated tar and ZIP files as ZIP files
Medium
Local
Low
None
pip handles concatenated tar and ZIP files as ZIP files regardless of filename or whether a file is both a tar and ZIP file. This behavior could result in confusing installation behavior, such as installing "incorrect" files according to the filename of the archive. New behavior only proceeds with installation if the file identifies uniquely as a ZIP or tar archive, not as both. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 142 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-1703
PYSEC-2026-1796
GHSA-6vgw-5pg2-w6jp
Jul 07, 2026
pip Path Traversal vulnerability
Medium
Network
Low
Low
When pip is installing and extracting a maliciously crafted wheel archive, files may be extracted outside the installation directory. The path traversal is limited to prefixes of the installation directory, thus isn't able to inject or overwrite executable files in typical situations. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 140 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-8869
PYSEC-2026-1795
GHSA-4xh5-x5gv-qwph
Jul 07, 2026
pip's fallback tar extraction doesn't check symbolic links point to extraction directory
High
Network
Low
None
When extracting a tar archive pip may not check symbolic links point into the extraction directory if the tarfile module doesn't implement PEP 706. Note that upgrading pip to a "fixed" version for this vulnerability doesn't fix all known vulnerabilities that are remediated by using a Python version that implements PEP 706. Note that this is a vulnerability in pip's fallback implementation of tar extraction for Python versions that don't implement PEP 706 and therefore are not secure to all vulnerabilities in the Python 'tarfile' module. If you're using a Python version that implements PEP 706 then pip doesn't use the "vulnerable" fallback code. Mitigations include upgrading to a version of pip that includes the fix, upgrading to a Python version that implements PEP 706 (Python >=3.9.17, >=3.10.12, >=3.11.4, or >=3.12), applying the linked patch, or inspecting source distributions (sdists) before installation as is already a best-practice. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 139 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
25.3
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-8643
GHSA-wf93-45jw-7689
PYSEC-2026-196
Jun 01, 2026
pip: Path traversal in console_scripts/gui_scripts entry point names allows installing scripts outside of target directory
Medium
Local
Low
Low
pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 144 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
26.1
26.1.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.1.2
References Updated Sep 10, 2026 · Source: OSV.dev | ||
23.3.1
patch
6 CVEs
CVE-2026-13346
GHSA-qwm4-qh6w-59xr
PYSEC-2026-3721
Jul 29, 2026
pip would incorrectly handle doubly-encoded package URLs from indexes
Medium
Network
High
High
pip would incorrectly handle doubly-encoded package URLs from indexes allowing for files to be installed to arbitrary locations on disk even when installing wheels. This vulnerability requires downloading or installing a package from a malicious package index to succeed, malicious packages alone are not able to exploit this vulnerability. Note that this vulnerability only materially impacts users running Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 145 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
26.1
26.1.1
26.1.2
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.2.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-6357
PYSEC-2026-2876
GHSA-jp4c-xjxw-mgf9
Jul 13, 2026
pip Vulnerable to Inclusion of Functionality from Untrusted Control Sphere
Critical
Local
Low
High
pip prior to version 26.1 would run self-update check functionality after installing wheel files which required importing well-known Python modules names. These module imports were intentionally deferred to increase startup time of the pip CLI. The patch changes self-update functionality to run before wheels are installed to prevent newly-installed modules from being imported shortly after the installation of a wheel package. Users should still review package contents prior to installation. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 142 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-3219
PYSEC-2026-2875
GHSA-58qw-9mgm-455v
Jul 13, 2026
pip has an interpretation conflict due to handling both concatenated tar and ZIP files as ZIP files
Medium
Local
Low
None
pip handles concatenated tar and ZIP files as ZIP files regardless of filename or whether a file is both a tar and ZIP file. This behavior could result in confusing installation behavior, such as installing "incorrect" files according to the filename of the archive. New behavior only proceeds with installation if the file identifies uniquely as a ZIP or tar archive, not as both. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 142 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-1703
PYSEC-2026-1796
GHSA-6vgw-5pg2-w6jp
Jul 07, 2026
pip Path Traversal vulnerability
Medium
Network
Low
Low
When pip is installing and extracting a maliciously crafted wheel archive, files may be extracted outside the installation directory. The path traversal is limited to prefixes of the installation directory, thus isn't able to inject or overwrite executable files in typical situations. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 140 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-8869
PYSEC-2026-1795
GHSA-4xh5-x5gv-qwph
Jul 07, 2026
pip's fallback tar extraction doesn't check symbolic links point to extraction directory
High
Network
Low
None
When extracting a tar archive pip may not check symbolic links point into the extraction directory if the tarfile module doesn't implement PEP 706. Note that upgrading pip to a "fixed" version for this vulnerability doesn't fix all known vulnerabilities that are remediated by using a Python version that implements PEP 706. Note that this is a vulnerability in pip's fallback implementation of tar extraction for Python versions that don't implement PEP 706 and therefore are not secure to all vulnerabilities in the Python 'tarfile' module. If you're using a Python version that implements PEP 706 then pip doesn't use the "vulnerable" fallback code. Mitigations include upgrading to a version of pip that includes the fix, upgrading to a Python version that implements PEP 706 (Python >=3.9.17, >=3.10.12, >=3.11.4, or >=3.12), applying the linked patch, or inspecting source distributions (sdists) before installation as is already a best-practice. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 139 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
25.3
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-8643
GHSA-wf93-45jw-7689
PYSEC-2026-196
Jun 01, 2026
pip: Path traversal in console_scripts/gui_scripts entry point names allows installing scripts outside of target directory
Medium
Local
Low
Low
pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 144 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
26.1
26.1.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.1.2
References Updated Sep 10, 2026 · Source: OSV.dev | ||
23.3
minor
6 CVEs
CVE-2026-13346
GHSA-qwm4-qh6w-59xr
PYSEC-2026-3721
Jul 29, 2026
pip would incorrectly handle doubly-encoded package URLs from indexes
Medium
Network
High
High
pip would incorrectly handle doubly-encoded package URLs from indexes allowing for files to be installed to arbitrary locations on disk even when installing wheels. This vulnerability requires downloading or installing a package from a malicious package index to succeed, malicious packages alone are not able to exploit this vulnerability. Note that this vulnerability only materially impacts users running Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 145 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
26.1
26.1.1
26.1.2
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.2.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-6357
PYSEC-2026-2876
GHSA-jp4c-xjxw-mgf9
Jul 13, 2026
pip Vulnerable to Inclusion of Functionality from Untrusted Control Sphere
Critical
Local
Low
High
pip prior to version 26.1 would run self-update check functionality after installing wheel files which required importing well-known Python modules names. These module imports were intentionally deferred to increase startup time of the pip CLI. The patch changes self-update functionality to run before wheels are installed to prevent newly-installed modules from being imported shortly after the installation of a wheel package. Users should still review package contents prior to installation. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 142 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-3219
PYSEC-2026-2875
GHSA-58qw-9mgm-455v
Jul 13, 2026
pip has an interpretation conflict due to handling both concatenated tar and ZIP files as ZIP files
Medium
Local
Low
None
pip handles concatenated tar and ZIP files as ZIP files regardless of filename or whether a file is both a tar and ZIP file. This behavior could result in confusing installation behavior, such as installing "incorrect" files according to the filename of the archive. New behavior only proceeds with installation if the file identifies uniquely as a ZIP or tar archive, not as both. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 142 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-1703
PYSEC-2026-1796
GHSA-6vgw-5pg2-w6jp
Jul 07, 2026
pip Path Traversal vulnerability
Medium
Network
Low
Low
When pip is installing and extracting a maliciously crafted wheel archive, files may be extracted outside the installation directory. The path traversal is limited to prefixes of the installation directory, thus isn't able to inject or overwrite executable files in typical situations. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 140 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-8869
PYSEC-2026-1795
GHSA-4xh5-x5gv-qwph
Jul 07, 2026
pip's fallback tar extraction doesn't check symbolic links point to extraction directory
High
Network
Low
None
When extracting a tar archive pip may not check symbolic links point into the extraction directory if the tarfile module doesn't implement PEP 706. Note that upgrading pip to a "fixed" version for this vulnerability doesn't fix all known vulnerabilities that are remediated by using a Python version that implements PEP 706. Note that this is a vulnerability in pip's fallback implementation of tar extraction for Python versions that don't implement PEP 706 and therefore are not secure to all vulnerabilities in the Python 'tarfile' module. If you're using a Python version that implements PEP 706 then pip doesn't use the "vulnerable" fallback code. Mitigations include upgrading to a version of pip that includes the fix, upgrading to a Python version that implements PEP 706 (Python >=3.9.17, >=3.10.12, >=3.11.4, or >=3.12), applying the linked patch, or inspecting source distributions (sdists) before installation as is already a best-practice. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 139 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
25.3
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-8643
GHSA-wf93-45jw-7689
PYSEC-2026-196
Jun 01, 2026
pip: Path traversal in console_scripts/gui_scripts entry point names allows installing scripts outside of target directory
Medium
Local
Low
Low
pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 144 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
26.1
26.1.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.1.2
References Updated Sep 10, 2026 · Source: OSV.dev | ||
23.2.1
patch
7 CVEs
CVE-2026-13346
GHSA-qwm4-qh6w-59xr
PYSEC-2026-3721
Jul 29, 2026
pip would incorrectly handle doubly-encoded package URLs from indexes
Medium
Network
High
High
pip would incorrectly handle doubly-encoded package URLs from indexes allowing for files to be installed to arbitrary locations on disk even when installing wheels. This vulnerability requires downloading or installing a package from a malicious package index to succeed, malicious packages alone are not able to exploit this vulnerability. Note that this vulnerability only materially impacts users running Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 145 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
26.1
26.1.1
26.1.2
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.2.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-6357
PYSEC-2026-2876
GHSA-jp4c-xjxw-mgf9
Jul 13, 2026
pip Vulnerable to Inclusion of Functionality from Untrusted Control Sphere
Critical
Local
Low
High
pip prior to version 26.1 would run self-update check functionality after installing wheel files which required importing well-known Python modules names. These module imports were intentionally deferred to increase startup time of the pip CLI. The patch changes self-update functionality to run before wheels are installed to prevent newly-installed modules from being imported shortly after the installation of a wheel package. Users should still review package contents prior to installation. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 142 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-3219
PYSEC-2026-2875
GHSA-58qw-9mgm-455v
Jul 13, 2026
pip has an interpretation conflict due to handling both concatenated tar and ZIP files as ZIP files
Medium
Local
Low
None
pip handles concatenated tar and ZIP files as ZIP files regardless of filename or whether a file is both a tar and ZIP file. This behavior could result in confusing installation behavior, such as installing "incorrect" files according to the filename of the archive. New behavior only proceeds with installation if the file identifies uniquely as a ZIP or tar archive, not as both. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 142 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-1703
PYSEC-2026-1796
GHSA-6vgw-5pg2-w6jp
Jul 07, 2026
pip Path Traversal vulnerability
Medium
Network
Low
Low
When pip is installing and extracting a maliciously crafted wheel archive, files may be extracted outside the installation directory. The path traversal is limited to prefixes of the installation directory, thus isn't able to inject or overwrite executable files in typical situations. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 140 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-8869
PYSEC-2026-1795
GHSA-4xh5-x5gv-qwph
Jul 07, 2026
pip's fallback tar extraction doesn't check symbolic links point to extraction directory
High
Network
Low
None
When extracting a tar archive pip may not check symbolic links point into the extraction directory if the tarfile module doesn't implement PEP 706. Note that upgrading pip to a "fixed" version for this vulnerability doesn't fix all known vulnerabilities that are remediated by using a Python version that implements PEP 706. Note that this is a vulnerability in pip's fallback implementation of tar extraction for Python versions that don't implement PEP 706 and therefore are not secure to all vulnerabilities in the Python 'tarfile' module. If you're using a Python version that implements PEP 706 then pip doesn't use the "vulnerable" fallback code. Mitigations include upgrading to a version of pip that includes the fix, upgrading to a Python version that implements PEP 706 (Python >=3.9.17, >=3.10.12, >=3.11.4, or >=3.12), applying the linked patch, or inspecting source distributions (sdists) before installation as is already a best-practice. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 139 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
25.3
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-8643
GHSA-wf93-45jw-7689
PYSEC-2026-196
Jun 01, 2026
pip: Path traversal in console_scripts/gui_scripts entry point names allows installing scripts outside of target directory
Medium
Local
Low
Low
pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 144 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
26.1
26.1.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.1.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-5752
GHSA-mq26-g339-26xf
PYSEC-2023-228
Oct 25, 2023
Command Injection in pip when used with Mercurial
Medium
Local
Low
Low
None
When installing a package from a Mercurial VCS URL, e.g. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 122 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
23.3
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
23.2
minor
7 CVEs
CVE-2026-13346
GHSA-qwm4-qh6w-59xr
PYSEC-2026-3721
Jul 29, 2026
pip would incorrectly handle doubly-encoded package URLs from indexes
Medium
Network
High
High
pip would incorrectly handle doubly-encoded package URLs from indexes allowing for files to be installed to arbitrary locations on disk even when installing wheels. This vulnerability requires downloading or installing a package from a malicious package index to succeed, malicious packages alone are not able to exploit this vulnerability. Note that this vulnerability only materially impacts users running Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 145 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
26.1
26.1.1
26.1.2
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.2.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-6357
PYSEC-2026-2876
GHSA-jp4c-xjxw-mgf9
Jul 13, 2026
pip Vulnerable to Inclusion of Functionality from Untrusted Control Sphere
Critical
Local
Low
High
pip prior to version 26.1 would run self-update check functionality after installing wheel files which required importing well-known Python modules names. These module imports were intentionally deferred to increase startup time of the pip CLI. The patch changes self-update functionality to run before wheels are installed to prevent newly-installed modules from being imported shortly after the installation of a wheel package. Users should still review package contents prior to installation. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 142 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-3219
PYSEC-2026-2875
GHSA-58qw-9mgm-455v
Jul 13, 2026
pip has an interpretation conflict due to handling both concatenated tar and ZIP files as ZIP files
Medium
Local
Low
None
pip handles concatenated tar and ZIP files as ZIP files regardless of filename or whether a file is both a tar and ZIP file. This behavior could result in confusing installation behavior, such as installing "incorrect" files according to the filename of the archive. New behavior only proceeds with installation if the file identifies uniquely as a ZIP or tar archive, not as both. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 142 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-1703
PYSEC-2026-1796
GHSA-6vgw-5pg2-w6jp
Jul 07, 2026
pip Path Traversal vulnerability
Medium
Network
Low
Low
When pip is installing and extracting a maliciously crafted wheel archive, files may be extracted outside the installation directory. The path traversal is limited to prefixes of the installation directory, thus isn't able to inject or overwrite executable files in typical situations. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 140 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-8869
PYSEC-2026-1795
GHSA-4xh5-x5gv-qwph
Jul 07, 2026
pip's fallback tar extraction doesn't check symbolic links point to extraction directory
High
Network
Low
None
When extracting a tar archive pip may not check symbolic links point into the extraction directory if the tarfile module doesn't implement PEP 706. Note that upgrading pip to a "fixed" version for this vulnerability doesn't fix all known vulnerabilities that are remediated by using a Python version that implements PEP 706. Note that this is a vulnerability in pip's fallback implementation of tar extraction for Python versions that don't implement PEP 706 and therefore are not secure to all vulnerabilities in the Python 'tarfile' module. If you're using a Python version that implements PEP 706 then pip doesn't use the "vulnerable" fallback code. Mitigations include upgrading to a version of pip that includes the fix, upgrading to a Python version that implements PEP 706 (Python >=3.9.17, >=3.10.12, >=3.11.4, or >=3.12), applying the linked patch, or inspecting source distributions (sdists) before installation as is already a best-practice. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 139 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
25.3
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-8643
GHSA-wf93-45jw-7689
PYSEC-2026-196
Jun 01, 2026
pip: Path traversal in console_scripts/gui_scripts entry point names allows installing scripts outside of target directory
Medium
Local
Low
Low
pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 144 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
26.1
26.1.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.1.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-5752
GHSA-mq26-g339-26xf
PYSEC-2023-228
Oct 25, 2023
Command Injection in pip when used with Mercurial
Medium
Local
Low
Low
None
When installing a package from a Mercurial VCS URL, e.g. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 122 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
23.3
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
23.1.2
patch
7 CVEs
CVE-2026-13346
GHSA-qwm4-qh6w-59xr
PYSEC-2026-3721
Jul 29, 2026
pip would incorrectly handle doubly-encoded package URLs from indexes
Medium
Network
High
High
pip would incorrectly handle doubly-encoded package URLs from indexes allowing for files to be installed to arbitrary locations on disk even when installing wheels. This vulnerability requires downloading or installing a package from a malicious package index to succeed, malicious packages alone are not able to exploit this vulnerability. Note that this vulnerability only materially impacts users running Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 145 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
26.1
26.1.1
26.1.2
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.2.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-6357
PYSEC-2026-2876
GHSA-jp4c-xjxw-mgf9
Jul 13, 2026
pip Vulnerable to Inclusion of Functionality from Untrusted Control Sphere
Critical
Local
Low
High
pip prior to version 26.1 would run self-update check functionality after installing wheel files which required importing well-known Python modules names. These module imports were intentionally deferred to increase startup time of the pip CLI. The patch changes self-update functionality to run before wheels are installed to prevent newly-installed modules from being imported shortly after the installation of a wheel package. Users should still review package contents prior to installation. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 142 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-3219
PYSEC-2026-2875
GHSA-58qw-9mgm-455v
Jul 13, 2026
pip has an interpretation conflict due to handling both concatenated tar and ZIP files as ZIP files
Medium
Local
Low
None
pip handles concatenated tar and ZIP files as ZIP files regardless of filename or whether a file is both a tar and ZIP file. This behavior could result in confusing installation behavior, such as installing "incorrect" files according to the filename of the archive. New behavior only proceeds with installation if the file identifies uniquely as a ZIP or tar archive, not as both. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 142 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-1703
PYSEC-2026-1796
GHSA-6vgw-5pg2-w6jp
Jul 07, 2026
pip Path Traversal vulnerability
Medium
Network
Low
Low
When pip is installing and extracting a maliciously crafted wheel archive, files may be extracted outside the installation directory. The path traversal is limited to prefixes of the installation directory, thus isn't able to inject or overwrite executable files in typical situations. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 140 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-8869
PYSEC-2026-1795
GHSA-4xh5-x5gv-qwph
Jul 07, 2026
pip's fallback tar extraction doesn't check symbolic links point to extraction directory
High
Network
Low
None
When extracting a tar archive pip may not check symbolic links point into the extraction directory if the tarfile module doesn't implement PEP 706. Note that upgrading pip to a "fixed" version for this vulnerability doesn't fix all known vulnerabilities that are remediated by using a Python version that implements PEP 706. Note that this is a vulnerability in pip's fallback implementation of tar extraction for Python versions that don't implement PEP 706 and therefore are not secure to all vulnerabilities in the Python 'tarfile' module. If you're using a Python version that implements PEP 706 then pip doesn't use the "vulnerable" fallback code. Mitigations include upgrading to a version of pip that includes the fix, upgrading to a Python version that implements PEP 706 (Python >=3.9.17, >=3.10.12, >=3.11.4, or >=3.12), applying the linked patch, or inspecting source distributions (sdists) before installation as is already a best-practice. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 139 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
25.3
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-8643
GHSA-wf93-45jw-7689
PYSEC-2026-196
Jun 01, 2026
pip: Path traversal in console_scripts/gui_scripts entry point names allows installing scripts outside of target directory
Medium
Local
Low
Low
pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 144 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
26.1
26.1.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.1.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-5752
GHSA-mq26-g339-26xf
PYSEC-2023-228
Oct 25, 2023
Command Injection in pip when used with Mercurial
Medium
Local
Low
Low
None
When installing a package from a Mercurial VCS URL, e.g. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 122 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
23.3
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
23.1.1
patch
7 CVEs
CVE-2026-13346
GHSA-qwm4-qh6w-59xr
PYSEC-2026-3721
Jul 29, 2026
pip would incorrectly handle doubly-encoded package URLs from indexes
Medium
Network
High
High
pip would incorrectly handle doubly-encoded package URLs from indexes allowing for files to be installed to arbitrary locations on disk even when installing wheels. This vulnerability requires downloading or installing a package from a malicious package index to succeed, malicious packages alone are not able to exploit this vulnerability. Note that this vulnerability only materially impacts users running Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 145 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
26.1
26.1.1
26.1.2
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.2.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-6357
PYSEC-2026-2876
GHSA-jp4c-xjxw-mgf9
Jul 13, 2026
pip Vulnerable to Inclusion of Functionality from Untrusted Control Sphere
Critical
Local
Low
High
pip prior to version 26.1 would run self-update check functionality after installing wheel files which required importing well-known Python modules names. These module imports were intentionally deferred to increase startup time of the pip CLI. The patch changes self-update functionality to run before wheels are installed to prevent newly-installed modules from being imported shortly after the installation of a wheel package. Users should still review package contents prior to installation. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 142 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-3219
PYSEC-2026-2875
GHSA-58qw-9mgm-455v
Jul 13, 2026
pip has an interpretation conflict due to handling both concatenated tar and ZIP files as ZIP files
Medium
Local
Low
None
pip handles concatenated tar and ZIP files as ZIP files regardless of filename or whether a file is both a tar and ZIP file. This behavior could result in confusing installation behavior, such as installing "incorrect" files according to the filename of the archive. New behavior only proceeds with installation if the file identifies uniquely as a ZIP or tar archive, not as both. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 142 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-1703
PYSEC-2026-1796
GHSA-6vgw-5pg2-w6jp
Jul 07, 2026
pip Path Traversal vulnerability
Medium
Network
Low
Low
When pip is installing and extracting a maliciously crafted wheel archive, files may be extracted outside the installation directory. The path traversal is limited to prefixes of the installation directory, thus isn't able to inject or overwrite executable files in typical situations. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 140 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-8869
PYSEC-2026-1795
GHSA-4xh5-x5gv-qwph
Jul 07, 2026
pip's fallback tar extraction doesn't check symbolic links point to extraction directory
High
Network
Low
None
When extracting a tar archive pip may not check symbolic links point into the extraction directory if the tarfile module doesn't implement PEP 706. Note that upgrading pip to a "fixed" version for this vulnerability doesn't fix all known vulnerabilities that are remediated by using a Python version that implements PEP 706. Note that this is a vulnerability in pip's fallback implementation of tar extraction for Python versions that don't implement PEP 706 and therefore are not secure to all vulnerabilities in the Python 'tarfile' module. If you're using a Python version that implements PEP 706 then pip doesn't use the "vulnerable" fallback code. Mitigations include upgrading to a version of pip that includes the fix, upgrading to a Python version that implements PEP 706 (Python >=3.9.17, >=3.10.12, >=3.11.4, or >=3.12), applying the linked patch, or inspecting source distributions (sdists) before installation as is already a best-practice. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 139 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
25.3
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-8643
GHSA-wf93-45jw-7689
PYSEC-2026-196
Jun 01, 2026
pip: Path traversal in console_scripts/gui_scripts entry point names allows installing scripts outside of target directory
Medium
Local
Low
Low
pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 144 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
26.1
26.1.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.1.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-5752
GHSA-mq26-g339-26xf
PYSEC-2023-228
Oct 25, 2023
Command Injection in pip when used with Mercurial
Medium
Local
Low
Low
None
When installing a package from a Mercurial VCS URL, e.g. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 122 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
23.3
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
23.1
minor
7 CVEs
CVE-2026-13346
GHSA-qwm4-qh6w-59xr
PYSEC-2026-3721
Jul 29, 2026
pip would incorrectly handle doubly-encoded package URLs from indexes
Medium
Network
High
High
pip would incorrectly handle doubly-encoded package URLs from indexes allowing for files to be installed to arbitrary locations on disk even when installing wheels. This vulnerability requires downloading or installing a package from a malicious package index to succeed, malicious packages alone are not able to exploit this vulnerability. Note that this vulnerability only materially impacts users running Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 145 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
26.1
26.1.1
26.1.2
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.2.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-6357
PYSEC-2026-2876
GHSA-jp4c-xjxw-mgf9
Jul 13, 2026
pip Vulnerable to Inclusion of Functionality from Untrusted Control Sphere
Critical
Local
Low
High
pip prior to version 26.1 would run self-update check functionality after installing wheel files which required importing well-known Python modules names. These module imports were intentionally deferred to increase startup time of the pip CLI. The patch changes self-update functionality to run before wheels are installed to prevent newly-installed modules from being imported shortly after the installation of a wheel package. Users should still review package contents prior to installation. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 142 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-3219
PYSEC-2026-2875
GHSA-58qw-9mgm-455v
Jul 13, 2026
pip has an interpretation conflict due to handling both concatenated tar and ZIP files as ZIP files
Medium
Local
Low
None
pip handles concatenated tar and ZIP files as ZIP files regardless of filename or whether a file is both a tar and ZIP file. This behavior could result in confusing installation behavior, such as installing "incorrect" files according to the filename of the archive. New behavior only proceeds with installation if the file identifies uniquely as a ZIP or tar archive, not as both. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 142 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-1703
PYSEC-2026-1796
GHSA-6vgw-5pg2-w6jp
Jul 07, 2026
pip Path Traversal vulnerability
Medium
Network
Low
Low
When pip is installing and extracting a maliciously crafted wheel archive, files may be extracted outside the installation directory. The path traversal is limited to prefixes of the installation directory, thus isn't able to inject or overwrite executable files in typical situations. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 140 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-8869
PYSEC-2026-1795
GHSA-4xh5-x5gv-qwph
Jul 07, 2026
pip's fallback tar extraction doesn't check symbolic links point to extraction directory
High
Network
Low
None
When extracting a tar archive pip may not check symbolic links point into the extraction directory if the tarfile module doesn't implement PEP 706. Note that upgrading pip to a "fixed" version for this vulnerability doesn't fix all known vulnerabilities that are remediated by using a Python version that implements PEP 706. Note that this is a vulnerability in pip's fallback implementation of tar extraction for Python versions that don't implement PEP 706 and therefore are not secure to all vulnerabilities in the Python 'tarfile' module. If you're using a Python version that implements PEP 706 then pip doesn't use the "vulnerable" fallback code. Mitigations include upgrading to a version of pip that includes the fix, upgrading to a Python version that implements PEP 706 (Python >=3.9.17, >=3.10.12, >=3.11.4, or >=3.12), applying the linked patch, or inspecting source distributions (sdists) before installation as is already a best-practice. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 139 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
25.3
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-8643
GHSA-wf93-45jw-7689
PYSEC-2026-196
Jun 01, 2026
pip: Path traversal in console_scripts/gui_scripts entry point names allows installing scripts outside of target directory
Medium
Local
Low
Low
pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 144 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
26.1
26.1.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.1.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-5752
GHSA-mq26-g339-26xf
PYSEC-2023-228
Oct 25, 2023
Command Injection in pip when used with Mercurial
Medium
Local
Low
Low
None
When installing a package from a Mercurial VCS URL, e.g. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 122 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
23.3
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
23.0.1
patch
7 CVEs
CVE-2026-13346
GHSA-qwm4-qh6w-59xr
PYSEC-2026-3721
Jul 29, 2026
pip would incorrectly handle doubly-encoded package URLs from indexes
Medium
Network
High
High
pip would incorrectly handle doubly-encoded package URLs from indexes allowing for files to be installed to arbitrary locations on disk even when installing wheels. This vulnerability requires downloading or installing a package from a malicious package index to succeed, malicious packages alone are not able to exploit this vulnerability. Note that this vulnerability only materially impacts users running Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 145 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
26.1
26.1.1
26.1.2
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.2.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-6357
PYSEC-2026-2876
GHSA-jp4c-xjxw-mgf9
Jul 13, 2026
pip Vulnerable to Inclusion of Functionality from Untrusted Control Sphere
Critical
Local
Low
High
pip prior to version 26.1 would run self-update check functionality after installing wheel files which required importing well-known Python modules names. These module imports were intentionally deferred to increase startup time of the pip CLI. The patch changes self-update functionality to run before wheels are installed to prevent newly-installed modules from being imported shortly after the installation of a wheel package. Users should still review package contents prior to installation. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 142 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-3219
PYSEC-2026-2875
GHSA-58qw-9mgm-455v
Jul 13, 2026
pip has an interpretation conflict due to handling both concatenated tar and ZIP files as ZIP files
Medium
Local
Low
None
pip handles concatenated tar and ZIP files as ZIP files regardless of filename or whether a file is both a tar and ZIP file. This behavior could result in confusing installation behavior, such as installing "incorrect" files according to the filename of the archive. New behavior only proceeds with installation if the file identifies uniquely as a ZIP or tar archive, not as both. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 142 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-1703
PYSEC-2026-1796
GHSA-6vgw-5pg2-w6jp
Jul 07, 2026
pip Path Traversal vulnerability
Medium
Network
Low
Low
When pip is installing and extracting a maliciously crafted wheel archive, files may be extracted outside the installation directory. The path traversal is limited to prefixes of the installation directory, thus isn't able to inject or overwrite executable files in typical situations. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 140 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-8869
PYSEC-2026-1795
GHSA-4xh5-x5gv-qwph
Jul 07, 2026
pip's fallback tar extraction doesn't check symbolic links point to extraction directory
High
Network
Low
None
When extracting a tar archive pip may not check symbolic links point into the extraction directory if the tarfile module doesn't implement PEP 706. Note that upgrading pip to a "fixed" version for this vulnerability doesn't fix all known vulnerabilities that are remediated by using a Python version that implements PEP 706. Note that this is a vulnerability in pip's fallback implementation of tar extraction for Python versions that don't implement PEP 706 and therefore are not secure to all vulnerabilities in the Python 'tarfile' module. If you're using a Python version that implements PEP 706 then pip doesn't use the "vulnerable" fallback code. Mitigations include upgrading to a version of pip that includes the fix, upgrading to a Python version that implements PEP 706 (Python >=3.9.17, >=3.10.12, >=3.11.4, or >=3.12), applying the linked patch, or inspecting source distributions (sdists) before installation as is already a best-practice. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 139 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
25.3
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-8643
GHSA-wf93-45jw-7689
PYSEC-2026-196
Jun 01, 2026
pip: Path traversal in console_scripts/gui_scripts entry point names allows installing scripts outside of target directory
Medium
Local
Low
Low
pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 144 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
26.1
26.1.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.1.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-5752
GHSA-mq26-g339-26xf
PYSEC-2023-228
Oct 25, 2023
Command Injection in pip when used with Mercurial
Medium
Local
Low
Low
None
When installing a package from a Mercurial VCS URL, e.g. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 122 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
23.3
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
23.0
major
7 CVEs
CVE-2026-13346
GHSA-qwm4-qh6w-59xr
PYSEC-2026-3721
Jul 29, 2026
pip would incorrectly handle doubly-encoded package URLs from indexes
Medium
Network
High
High
pip would incorrectly handle doubly-encoded package URLs from indexes allowing for files to be installed to arbitrary locations on disk even when installing wheels. This vulnerability requires downloading or installing a package from a malicious package index to succeed, malicious packages alone are not able to exploit this vulnerability. Note that this vulnerability only materially impacts users running Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 145 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
26.1
26.1.1
26.1.2
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.2.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-6357
PYSEC-2026-2876
GHSA-jp4c-xjxw-mgf9
Jul 13, 2026
pip Vulnerable to Inclusion of Functionality from Untrusted Control Sphere
Critical
Local
Low
High
pip prior to version 26.1 would run self-update check functionality after installing wheel files which required importing well-known Python modules names. These module imports were intentionally deferred to increase startup time of the pip CLI. The patch changes self-update functionality to run before wheels are installed to prevent newly-installed modules from being imported shortly after the installation of a wheel package. Users should still review package contents prior to installation. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 142 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-3219
PYSEC-2026-2875
GHSA-58qw-9mgm-455v
Jul 13, 2026
pip has an interpretation conflict due to handling both concatenated tar and ZIP files as ZIP files
Medium
Local
Low
None
pip handles concatenated tar and ZIP files as ZIP files regardless of filename or whether a file is both a tar and ZIP file. This behavior could result in confusing installation behavior, such as installing "incorrect" files according to the filename of the archive. New behavior only proceeds with installation if the file identifies uniquely as a ZIP or tar archive, not as both. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 142 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-1703
PYSEC-2026-1796
GHSA-6vgw-5pg2-w6jp
Jul 07, 2026
pip Path Traversal vulnerability
Medium
Network
Low
Low
When pip is installing and extracting a maliciously crafted wheel archive, files may be extracted outside the installation directory. The path traversal is limited to prefixes of the installation directory, thus isn't able to inject or overwrite executable files in typical situations. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 140 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-8869
PYSEC-2026-1795
GHSA-4xh5-x5gv-qwph
Jul 07, 2026
pip's fallback tar extraction doesn't check symbolic links point to extraction directory
High
Network
Low
None
When extracting a tar archive pip may not check symbolic links point into the extraction directory if the tarfile module doesn't implement PEP 706. Note that upgrading pip to a "fixed" version for this vulnerability doesn't fix all known vulnerabilities that are remediated by using a Python version that implements PEP 706. Note that this is a vulnerability in pip's fallback implementation of tar extraction for Python versions that don't implement PEP 706 and therefore are not secure to all vulnerabilities in the Python 'tarfile' module. If you're using a Python version that implements PEP 706 then pip doesn't use the "vulnerable" fallback code. Mitigations include upgrading to a version of pip that includes the fix, upgrading to a Python version that implements PEP 706 (Python >=3.9.17, >=3.10.12, >=3.11.4, or >=3.12), applying the linked patch, or inspecting source distributions (sdists) before installation as is already a best-practice. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 139 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
25.3
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-8643
GHSA-wf93-45jw-7689
PYSEC-2026-196
Jun 01, 2026
pip: Path traversal in console_scripts/gui_scripts entry point names allows installing scripts outside of target directory
Medium
Local
Low
Low
pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 144 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
26.1
26.1.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.1.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-5752
GHSA-mq26-g339-26xf
PYSEC-2023-228
Oct 25, 2023
Command Injection in pip when used with Mercurial
Medium
Local
Low
Low
None
When installing a package from a Mercurial VCS URL, e.g. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 122 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
23.3
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
22.3.1
patch
7 CVEs
CVE-2026-13346
GHSA-qwm4-qh6w-59xr
PYSEC-2026-3721
Jul 29, 2026
pip would incorrectly handle doubly-encoded package URLs from indexes
Medium
Network
High
High
pip would incorrectly handle doubly-encoded package URLs from indexes allowing for files to be installed to arbitrary locations on disk even when installing wheels. This vulnerability requires downloading or installing a package from a malicious package index to succeed, malicious packages alone are not able to exploit this vulnerability. Note that this vulnerability only materially impacts users running Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 145 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
26.1
26.1.1
26.1.2
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.2.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-6357
PYSEC-2026-2876
GHSA-jp4c-xjxw-mgf9
Jul 13, 2026
pip Vulnerable to Inclusion of Functionality from Untrusted Control Sphere
Critical
Local
Low
High
pip prior to version 26.1 would run self-update check functionality after installing wheel files which required importing well-known Python modules names. These module imports were intentionally deferred to increase startup time of the pip CLI. The patch changes self-update functionality to run before wheels are installed to prevent newly-installed modules from being imported shortly after the installation of a wheel package. Users should still review package contents prior to installation. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 142 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-3219
PYSEC-2026-2875
GHSA-58qw-9mgm-455v
Jul 13, 2026
pip has an interpretation conflict due to handling both concatenated tar and ZIP files as ZIP files
Medium
Local
Low
None
pip handles concatenated tar and ZIP files as ZIP files regardless of filename or whether a file is both a tar and ZIP file. This behavior could result in confusing installation behavior, such as installing "incorrect" files according to the filename of the archive. New behavior only proceeds with installation if the file identifies uniquely as a ZIP or tar archive, not as both. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 142 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-1703
PYSEC-2026-1796
GHSA-6vgw-5pg2-w6jp
Jul 07, 2026
pip Path Traversal vulnerability
Medium
Network
Low
Low
When pip is installing and extracting a maliciously crafted wheel archive, files may be extracted outside the installation directory. The path traversal is limited to prefixes of the installation directory, thus isn't able to inject or overwrite executable files in typical situations. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 140 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-8869
PYSEC-2026-1795
GHSA-4xh5-x5gv-qwph
Jul 07, 2026
pip's fallback tar extraction doesn't check symbolic links point to extraction directory
High
Network
Low
None
When extracting a tar archive pip may not check symbolic links point into the extraction directory if the tarfile module doesn't implement PEP 706. Note that upgrading pip to a "fixed" version for this vulnerability doesn't fix all known vulnerabilities that are remediated by using a Python version that implements PEP 706. Note that this is a vulnerability in pip's fallback implementation of tar extraction for Python versions that don't implement PEP 706 and therefore are not secure to all vulnerabilities in the Python 'tarfile' module. If you're using a Python version that implements PEP 706 then pip doesn't use the "vulnerable" fallback code. Mitigations include upgrading to a version of pip that includes the fix, upgrading to a Python version that implements PEP 706 (Python >=3.9.17, >=3.10.12, >=3.11.4, or >=3.12), applying the linked patch, or inspecting source distributions (sdists) before installation as is already a best-practice. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 139 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
25.3
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-8643
GHSA-wf93-45jw-7689
PYSEC-2026-196
Jun 01, 2026
pip: Path traversal in console_scripts/gui_scripts entry point names allows installing scripts outside of target directory
Medium
Local
Low
Low
pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 144 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
26.1
26.1.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.1.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-5752
GHSA-mq26-g339-26xf
PYSEC-2023-228
Oct 25, 2023
Command Injection in pip when used with Mercurial
Medium
Local
Low
Low
None
When installing a package from a Mercurial VCS URL, e.g. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 122 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
23.3
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
22.3
minor
7 CVEs
CVE-2026-13346
GHSA-qwm4-qh6w-59xr
PYSEC-2026-3721
Jul 29, 2026
pip would incorrectly handle doubly-encoded package URLs from indexes
Medium
Network
High
High
pip would incorrectly handle doubly-encoded package URLs from indexes allowing for files to be installed to arbitrary locations on disk even when installing wheels. This vulnerability requires downloading or installing a package from a malicious package index to succeed, malicious packages alone are not able to exploit this vulnerability. Note that this vulnerability only materially impacts users running Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 145 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
26.1
26.1.1
26.1.2
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.2.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-6357
PYSEC-2026-2876
GHSA-jp4c-xjxw-mgf9
Jul 13, 2026
pip Vulnerable to Inclusion of Functionality from Untrusted Control Sphere
Critical
Local
Low
High
pip prior to version 26.1 would run self-update check functionality after installing wheel files which required importing well-known Python modules names. These module imports were intentionally deferred to increase startup time of the pip CLI. The patch changes self-update functionality to run before wheels are installed to prevent newly-installed modules from being imported shortly after the installation of a wheel package. Users should still review package contents prior to installation. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 142 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-3219
PYSEC-2026-2875
GHSA-58qw-9mgm-455v
Jul 13, 2026
pip has an interpretation conflict due to handling both concatenated tar and ZIP files as ZIP files
Medium
Local
Low
None
pip handles concatenated tar and ZIP files as ZIP files regardless of filename or whether a file is both a tar and ZIP file. This behavior could result in confusing installation behavior, such as installing "incorrect" files according to the filename of the archive. New behavior only proceeds with installation if the file identifies uniquely as a ZIP or tar archive, not as both. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 142 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-1703
PYSEC-2026-1796
GHSA-6vgw-5pg2-w6jp
Jul 07, 2026
pip Path Traversal vulnerability
Medium
Network
Low
Low
When pip is installing and extracting a maliciously crafted wheel archive, files may be extracted outside the installation directory. The path traversal is limited to prefixes of the installation directory, thus isn't able to inject or overwrite executable files in typical situations. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 140 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-8869
PYSEC-2026-1795
GHSA-4xh5-x5gv-qwph
Jul 07, 2026
pip's fallback tar extraction doesn't check symbolic links point to extraction directory
High
Network
Low
None
When extracting a tar archive pip may not check symbolic links point into the extraction directory if the tarfile module doesn't implement PEP 706. Note that upgrading pip to a "fixed" version for this vulnerability doesn't fix all known vulnerabilities that are remediated by using a Python version that implements PEP 706. Note that this is a vulnerability in pip's fallback implementation of tar extraction for Python versions that don't implement PEP 706 and therefore are not secure to all vulnerabilities in the Python 'tarfile' module. If you're using a Python version that implements PEP 706 then pip doesn't use the "vulnerable" fallback code. Mitigations include upgrading to a version of pip that includes the fix, upgrading to a Python version that implements PEP 706 (Python >=3.9.17, >=3.10.12, >=3.11.4, or >=3.12), applying the linked patch, or inspecting source distributions (sdists) before installation as is already a best-practice. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 139 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
25.3
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-8643
GHSA-wf93-45jw-7689
PYSEC-2026-196
Jun 01, 2026
pip: Path traversal in console_scripts/gui_scripts entry point names allows installing scripts outside of target directory
Medium
Local
Low
Low
pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 144 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
26.1
26.1.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.1.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-5752
GHSA-mq26-g339-26xf
PYSEC-2023-228
Oct 25, 2023
Command Injection in pip when used with Mercurial
Medium
Local
Low
Low
None
When installing a package from a Mercurial VCS URL, e.g. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 122 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
23.3
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
22.2.2
patch
7 CVEs
CVE-2026-13346
GHSA-qwm4-qh6w-59xr
PYSEC-2026-3721
Jul 29, 2026
pip would incorrectly handle doubly-encoded package URLs from indexes
Medium
Network
High
High
pip would incorrectly handle doubly-encoded package URLs from indexes allowing for files to be installed to arbitrary locations on disk even when installing wheels. This vulnerability requires downloading or installing a package from a malicious package index to succeed, malicious packages alone are not able to exploit this vulnerability. Note that this vulnerability only materially impacts users running Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 145 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
26.1
26.1.1
26.1.2
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.2.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-6357
PYSEC-2026-2876
GHSA-jp4c-xjxw-mgf9
Jul 13, 2026
pip Vulnerable to Inclusion of Functionality from Untrusted Control Sphere
Critical
Local
Low
High
pip prior to version 26.1 would run self-update check functionality after installing wheel files which required importing well-known Python modules names. These module imports were intentionally deferred to increase startup time of the pip CLI. The patch changes self-update functionality to run before wheels are installed to prevent newly-installed modules from being imported shortly after the installation of a wheel package. Users should still review package contents prior to installation. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 142 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-3219
PYSEC-2026-2875
GHSA-58qw-9mgm-455v
Jul 13, 2026
pip has an interpretation conflict due to handling both concatenated tar and ZIP files as ZIP files
Medium
Local
Low
None
pip handles concatenated tar and ZIP files as ZIP files regardless of filename or whether a file is both a tar and ZIP file. This behavior could result in confusing installation behavior, such as installing "incorrect" files according to the filename of the archive. New behavior only proceeds with installation if the file identifies uniquely as a ZIP or tar archive, not as both. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 142 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-1703
PYSEC-2026-1796
GHSA-6vgw-5pg2-w6jp
Jul 07, 2026
pip Path Traversal vulnerability
Medium
Network
Low
Low
When pip is installing and extracting a maliciously crafted wheel archive, files may be extracted outside the installation directory. The path traversal is limited to prefixes of the installation directory, thus isn't able to inject or overwrite executable files in typical situations. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 140 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-8869
PYSEC-2026-1795
GHSA-4xh5-x5gv-qwph
Jul 07, 2026
pip's fallback tar extraction doesn't check symbolic links point to extraction directory
High
Network
Low
None
When extracting a tar archive pip may not check symbolic links point into the extraction directory if the tarfile module doesn't implement PEP 706. Note that upgrading pip to a "fixed" version for this vulnerability doesn't fix all known vulnerabilities that are remediated by using a Python version that implements PEP 706. Note that this is a vulnerability in pip's fallback implementation of tar extraction for Python versions that don't implement PEP 706 and therefore are not secure to all vulnerabilities in the Python 'tarfile' module. If you're using a Python version that implements PEP 706 then pip doesn't use the "vulnerable" fallback code. Mitigations include upgrading to a version of pip that includes the fix, upgrading to a Python version that implements PEP 706 (Python >=3.9.17, >=3.10.12, >=3.11.4, or >=3.12), applying the linked patch, or inspecting source distributions (sdists) before installation as is already a best-practice. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 139 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
25.3
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-8643
GHSA-wf93-45jw-7689
PYSEC-2026-196
Jun 01, 2026
pip: Path traversal in console_scripts/gui_scripts entry point names allows installing scripts outside of target directory
Medium
Local
Low
Low
pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 144 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
26.1
26.1.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.1.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-5752
GHSA-mq26-g339-26xf
PYSEC-2023-228
Oct 25, 2023
Command Injection in pip when used with Mercurial
Medium
Local
Low
Low
None
When installing a package from a Mercurial VCS URL, e.g. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 122 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
23.3
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
22.2.1
patch
7 CVEs
CVE-2026-13346
GHSA-qwm4-qh6w-59xr
PYSEC-2026-3721
Jul 29, 2026
pip would incorrectly handle doubly-encoded package URLs from indexes
Medium
Network
High
High
pip would incorrectly handle doubly-encoded package URLs from indexes allowing for files to be installed to arbitrary locations on disk even when installing wheels. This vulnerability requires downloading or installing a package from a malicious package index to succeed, malicious packages alone are not able to exploit this vulnerability. Note that this vulnerability only materially impacts users running Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 145 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
26.1
26.1.1
26.1.2
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.2.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-6357
PYSEC-2026-2876
GHSA-jp4c-xjxw-mgf9
Jul 13, 2026
pip Vulnerable to Inclusion of Functionality from Untrusted Control Sphere
Critical
Local
Low
High
pip prior to version 26.1 would run self-update check functionality after installing wheel files which required importing well-known Python modules names. These module imports were intentionally deferred to increase startup time of the pip CLI. The patch changes self-update functionality to run before wheels are installed to prevent newly-installed modules from being imported shortly after the installation of a wheel package. Users should still review package contents prior to installation. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 142 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-3219
PYSEC-2026-2875
GHSA-58qw-9mgm-455v
Jul 13, 2026
pip has an interpretation conflict due to handling both concatenated tar and ZIP files as ZIP files
Medium
Local
Low
None
pip handles concatenated tar and ZIP files as ZIP files regardless of filename or whether a file is both a tar and ZIP file. This behavior could result in confusing installation behavior, such as installing "incorrect" files according to the filename of the archive. New behavior only proceeds with installation if the file identifies uniquely as a ZIP or tar archive, not as both. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 142 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-1703
PYSEC-2026-1796
GHSA-6vgw-5pg2-w6jp
Jul 07, 2026
pip Path Traversal vulnerability
Medium
Network
Low
Low
When pip is installing and extracting a maliciously crafted wheel archive, files may be extracted outside the installation directory. The path traversal is limited to prefixes of the installation directory, thus isn't able to inject or overwrite executable files in typical situations. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 140 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-8869
PYSEC-2026-1795
GHSA-4xh5-x5gv-qwph
Jul 07, 2026
pip's fallback tar extraction doesn't check symbolic links point to extraction directory
High
Network
Low
None
When extracting a tar archive pip may not check symbolic links point into the extraction directory if the tarfile module doesn't implement PEP 706. Note that upgrading pip to a "fixed" version for this vulnerability doesn't fix all known vulnerabilities that are remediated by using a Python version that implements PEP 706. Note that this is a vulnerability in pip's fallback implementation of tar extraction for Python versions that don't implement PEP 706 and therefore are not secure to all vulnerabilities in the Python 'tarfile' module. If you're using a Python version that implements PEP 706 then pip doesn't use the "vulnerable" fallback code. Mitigations include upgrading to a version of pip that includes the fix, upgrading to a Python version that implements PEP 706 (Python >=3.9.17, >=3.10.12, >=3.11.4, or >=3.12), applying the linked patch, or inspecting source distributions (sdists) before installation as is already a best-practice. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 139 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
25.3
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-8643
GHSA-wf93-45jw-7689
PYSEC-2026-196
Jun 01, 2026
pip: Path traversal in console_scripts/gui_scripts entry point names allows installing scripts outside of target directory
Medium
Local
Low
Low
pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 144 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
26.1
26.1.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.1.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-5752
GHSA-mq26-g339-26xf
PYSEC-2023-228
Oct 25, 2023
Command Injection in pip when used with Mercurial
Medium
Local
Low
Low
None
When installing a package from a Mercurial VCS URL, e.g. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 122 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
23.3
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
22.2
minor
7 CVEs
CVE-2026-13346
GHSA-qwm4-qh6w-59xr
PYSEC-2026-3721
Jul 29, 2026
pip would incorrectly handle doubly-encoded package URLs from indexes
Medium
Network
High
High
pip would incorrectly handle doubly-encoded package URLs from indexes allowing for files to be installed to arbitrary locations on disk even when installing wheels. This vulnerability requires downloading or installing a package from a malicious package index to succeed, malicious packages alone are not able to exploit this vulnerability. Note that this vulnerability only materially impacts users running Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 145 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
26.1
26.1.1
26.1.2
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.2.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-6357
PYSEC-2026-2876
GHSA-jp4c-xjxw-mgf9
Jul 13, 2026
pip Vulnerable to Inclusion of Functionality from Untrusted Control Sphere
Critical
Local
Low
High
pip prior to version 26.1 would run self-update check functionality after installing wheel files which required importing well-known Python modules names. These module imports were intentionally deferred to increase startup time of the pip CLI. The patch changes self-update functionality to run before wheels are installed to prevent newly-installed modules from being imported shortly after the installation of a wheel package. Users should still review package contents prior to installation. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 142 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-3219
PYSEC-2026-2875
GHSA-58qw-9mgm-455v
Jul 13, 2026
pip has an interpretation conflict due to handling both concatenated tar and ZIP files as ZIP files
Medium
Local
Low
None
pip handles concatenated tar and ZIP files as ZIP files regardless of filename or whether a file is both a tar and ZIP file. This behavior could result in confusing installation behavior, such as installing "incorrect" files according to the filename of the archive. New behavior only proceeds with installation if the file identifies uniquely as a ZIP or tar archive, not as both. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 142 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-1703
PYSEC-2026-1796
GHSA-6vgw-5pg2-w6jp
Jul 07, 2026
pip Path Traversal vulnerability
Medium
Network
Low
Low
When pip is installing and extracting a maliciously crafted wheel archive, files may be extracted outside the installation directory. The path traversal is limited to prefixes of the installation directory, thus isn't able to inject or overwrite executable files in typical situations. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 140 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-8869
PYSEC-2026-1795
GHSA-4xh5-x5gv-qwph
Jul 07, 2026
pip's fallback tar extraction doesn't check symbolic links point to extraction directory
High
Network
Low
None
When extracting a tar archive pip may not check symbolic links point into the extraction directory if the tarfile module doesn't implement PEP 706. Note that upgrading pip to a "fixed" version for this vulnerability doesn't fix all known vulnerabilities that are remediated by using a Python version that implements PEP 706. Note that this is a vulnerability in pip's fallback implementation of tar extraction for Python versions that don't implement PEP 706 and therefore are not secure to all vulnerabilities in the Python 'tarfile' module. If you're using a Python version that implements PEP 706 then pip doesn't use the "vulnerable" fallback code. Mitigations include upgrading to a version of pip that includes the fix, upgrading to a Python version that implements PEP 706 (Python >=3.9.17, >=3.10.12, >=3.11.4, or >=3.12), applying the linked patch, or inspecting source distributions (sdists) before installation as is already a best-practice. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 139 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
25.3
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-8643
GHSA-wf93-45jw-7689
PYSEC-2026-196
Jun 01, 2026
pip: Path traversal in console_scripts/gui_scripts entry point names allows installing scripts outside of target directory
Medium
Local
Low
Low
pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 144 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
26.1
26.1.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.1.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-5752
GHSA-mq26-g339-26xf
PYSEC-2023-228
Oct 25, 2023
Command Injection in pip when used with Mercurial
Medium
Local
Low
Low
None
When installing a package from a Mercurial VCS URL, e.g. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 122 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
23.3
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
22.1.2
patch
7 CVEs
CVE-2026-13346
GHSA-qwm4-qh6w-59xr
PYSEC-2026-3721
Jul 29, 2026
pip would incorrectly handle doubly-encoded package URLs from indexes
Medium
Network
High
High
pip would incorrectly handle doubly-encoded package URLs from indexes allowing for files to be installed to arbitrary locations on disk even when installing wheels. This vulnerability requires downloading or installing a package from a malicious package index to succeed, malicious packages alone are not able to exploit this vulnerability. Note that this vulnerability only materially impacts users running Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 145 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
26.1
26.1.1
26.1.2
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.2.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-6357
PYSEC-2026-2876
GHSA-jp4c-xjxw-mgf9
Jul 13, 2026
pip Vulnerable to Inclusion of Functionality from Untrusted Control Sphere
Critical
Local
Low
High
pip prior to version 26.1 would run self-update check functionality after installing wheel files which required importing well-known Python modules names. These module imports were intentionally deferred to increase startup time of the pip CLI. The patch changes self-update functionality to run before wheels are installed to prevent newly-installed modules from being imported shortly after the installation of a wheel package. Users should still review package contents prior to installation. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 142 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-3219
PYSEC-2026-2875
GHSA-58qw-9mgm-455v
Jul 13, 2026
pip has an interpretation conflict due to handling both concatenated tar and ZIP files as ZIP files
Medium
Local
Low
None
pip handles concatenated tar and ZIP files as ZIP files regardless of filename or whether a file is both a tar and ZIP file. This behavior could result in confusing installation behavior, such as installing "incorrect" files according to the filename of the archive. New behavior only proceeds with installation if the file identifies uniquely as a ZIP or tar archive, not as both. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 142 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-1703
PYSEC-2026-1796
GHSA-6vgw-5pg2-w6jp
Jul 07, 2026
pip Path Traversal vulnerability
Medium
Network
Low
Low
When pip is installing and extracting a maliciously crafted wheel archive, files may be extracted outside the installation directory. The path traversal is limited to prefixes of the installation directory, thus isn't able to inject or overwrite executable files in typical situations. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 140 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-8869
PYSEC-2026-1795
GHSA-4xh5-x5gv-qwph
Jul 07, 2026
pip's fallback tar extraction doesn't check symbolic links point to extraction directory
High
Network
Low
None
When extracting a tar archive pip may not check symbolic links point into the extraction directory if the tarfile module doesn't implement PEP 706. Note that upgrading pip to a "fixed" version for this vulnerability doesn't fix all known vulnerabilities that are remediated by using a Python version that implements PEP 706. Note that this is a vulnerability in pip's fallback implementation of tar extraction for Python versions that don't implement PEP 706 and therefore are not secure to all vulnerabilities in the Python 'tarfile' module. If you're using a Python version that implements PEP 706 then pip doesn't use the "vulnerable" fallback code. Mitigations include upgrading to a version of pip that includes the fix, upgrading to a Python version that implements PEP 706 (Python >=3.9.17, >=3.10.12, >=3.11.4, or >=3.12), applying the linked patch, or inspecting source distributions (sdists) before installation as is already a best-practice. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 139 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
25.3
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-8643
GHSA-wf93-45jw-7689
PYSEC-2026-196
Jun 01, 2026
pip: Path traversal in console_scripts/gui_scripts entry point names allows installing scripts outside of target directory
Medium
Local
Low
Low
pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 144 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
26.1
26.1.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.1.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-5752
GHSA-mq26-g339-26xf
PYSEC-2023-228
Oct 25, 2023
Command Injection in pip when used with Mercurial
Medium
Local
Low
Low
None
When installing a package from a Mercurial VCS URL, e.g. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 122 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
23.3
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
22.1.1
patch
7 CVEs
CVE-2026-13346
GHSA-qwm4-qh6w-59xr
PYSEC-2026-3721
Jul 29, 2026
pip would incorrectly handle doubly-encoded package URLs from indexes
Medium
Network
High
High
pip would incorrectly handle doubly-encoded package URLs from indexes allowing for files to be installed to arbitrary locations on disk even when installing wheels. This vulnerability requires downloading or installing a package from a malicious package index to succeed, malicious packages alone are not able to exploit this vulnerability. Note that this vulnerability only materially impacts users running Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 145 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
26.1
26.1.1
26.1.2
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.2.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-6357
PYSEC-2026-2876
GHSA-jp4c-xjxw-mgf9
Jul 13, 2026
pip Vulnerable to Inclusion of Functionality from Untrusted Control Sphere
Critical
Local
Low
High
pip prior to version 26.1 would run self-update check functionality after installing wheel files which required importing well-known Python modules names. These module imports were intentionally deferred to increase startup time of the pip CLI. The patch changes self-update functionality to run before wheels are installed to prevent newly-installed modules from being imported shortly after the installation of a wheel package. Users should still review package contents prior to installation. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 142 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-3219
PYSEC-2026-2875
GHSA-58qw-9mgm-455v
Jul 13, 2026
pip has an interpretation conflict due to handling both concatenated tar and ZIP files as ZIP files
Medium
Local
Low
None
pip handles concatenated tar and ZIP files as ZIP files regardless of filename or whether a file is both a tar and ZIP file. This behavior could result in confusing installation behavior, such as installing "incorrect" files according to the filename of the archive. New behavior only proceeds with installation if the file identifies uniquely as a ZIP or tar archive, not as both. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 142 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-1703
PYSEC-2026-1796
GHSA-6vgw-5pg2-w6jp
Jul 07, 2026
pip Path Traversal vulnerability
Medium
Network
Low
Low
When pip is installing and extracting a maliciously crafted wheel archive, files may be extracted outside the installation directory. The path traversal is limited to prefixes of the installation directory, thus isn't able to inject or overwrite executable files in typical situations. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 140 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-8869
PYSEC-2026-1795
GHSA-4xh5-x5gv-qwph
Jul 07, 2026
pip's fallback tar extraction doesn't check symbolic links point to extraction directory
High
Network
Low
None
When extracting a tar archive pip may not check symbolic links point into the extraction directory if the tarfile module doesn't implement PEP 706. Note that upgrading pip to a "fixed" version for this vulnerability doesn't fix all known vulnerabilities that are remediated by using a Python version that implements PEP 706. Note that this is a vulnerability in pip's fallback implementation of tar extraction for Python versions that don't implement PEP 706 and therefore are not secure to all vulnerabilities in the Python 'tarfile' module. If you're using a Python version that implements PEP 706 then pip doesn't use the "vulnerable" fallback code. Mitigations include upgrading to a version of pip that includes the fix, upgrading to a Python version that implements PEP 706 (Python >=3.9.17, >=3.10.12, >=3.11.4, or >=3.12), applying the linked patch, or inspecting source distributions (sdists) before installation as is already a best-practice. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 139 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
25.3
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-8643
GHSA-wf93-45jw-7689
PYSEC-2026-196
Jun 01, 2026
pip: Path traversal in console_scripts/gui_scripts entry point names allows installing scripts outside of target directory
Medium
Local
Low
Low
pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 144 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
26.1
26.1.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.1.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-5752
GHSA-mq26-g339-26xf
PYSEC-2023-228
Oct 25, 2023
Command Injection in pip when used with Mercurial
Medium
Local
Low
Low
None
When installing a package from a Mercurial VCS URL, e.g. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 122 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
23.3
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
22.1
minor
7 CVEs
CVE-2026-13346
GHSA-qwm4-qh6w-59xr
PYSEC-2026-3721
Jul 29, 2026
pip would incorrectly handle doubly-encoded package URLs from indexes
Medium
Network
High
High
pip would incorrectly handle doubly-encoded package URLs from indexes allowing for files to be installed to arbitrary locations on disk even when installing wheels. This vulnerability requires downloading or installing a package from a malicious package index to succeed, malicious packages alone are not able to exploit this vulnerability. Note that this vulnerability only materially impacts users running Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 145 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
26.1
26.1.1
26.1.2
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.2.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-6357
PYSEC-2026-2876
GHSA-jp4c-xjxw-mgf9
Jul 13, 2026
pip Vulnerable to Inclusion of Functionality from Untrusted Control Sphere
Critical
Local
Low
High
pip prior to version 26.1 would run self-update check functionality after installing wheel files which required importing well-known Python modules names. These module imports were intentionally deferred to increase startup time of the pip CLI. The patch changes self-update functionality to run before wheels are installed to prevent newly-installed modules from being imported shortly after the installation of a wheel package. Users should still review package contents prior to installation. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 142 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-3219
PYSEC-2026-2875
GHSA-58qw-9mgm-455v
Jul 13, 2026
pip has an interpretation conflict due to handling both concatenated tar and ZIP files as ZIP files
Medium
Local
Low
None
pip handles concatenated tar and ZIP files as ZIP files regardless of filename or whether a file is both a tar and ZIP file. This behavior could result in confusing installation behavior, such as installing "incorrect" files according to the filename of the archive. New behavior only proceeds with installation if the file identifies uniquely as a ZIP or tar archive, not as both. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 142 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-1703
PYSEC-2026-1796
GHSA-6vgw-5pg2-w6jp
Jul 07, 2026
pip Path Traversal vulnerability
Medium
Network
Low
Low
When pip is installing and extracting a maliciously crafted wheel archive, files may be extracted outside the installation directory. The path traversal is limited to prefixes of the installation directory, thus isn't able to inject or overwrite executable files in typical situations. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 140 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-8869
PYSEC-2026-1795
GHSA-4xh5-x5gv-qwph
Jul 07, 2026
pip's fallback tar extraction doesn't check symbolic links point to extraction directory
High
Network
Low
None
When extracting a tar archive pip may not check symbolic links point into the extraction directory if the tarfile module doesn't implement PEP 706. Note that upgrading pip to a "fixed" version for this vulnerability doesn't fix all known vulnerabilities that are remediated by using a Python version that implements PEP 706. Note that this is a vulnerability in pip's fallback implementation of tar extraction for Python versions that don't implement PEP 706 and therefore are not secure to all vulnerabilities in the Python 'tarfile' module. If you're using a Python version that implements PEP 706 then pip doesn't use the "vulnerable" fallback code. Mitigations include upgrading to a version of pip that includes the fix, upgrading to a Python version that implements PEP 706 (Python >=3.9.17, >=3.10.12, >=3.11.4, or >=3.12), applying the linked patch, or inspecting source distributions (sdists) before installation as is already a best-practice. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 139 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
25.3
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-8643
GHSA-wf93-45jw-7689
PYSEC-2026-196
Jun 01, 2026
pip: Path traversal in console_scripts/gui_scripts entry point names allows installing scripts outside of target directory
Medium
Local
Low
Low
pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 144 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
26.1
26.1.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.1.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-5752
GHSA-mq26-g339-26xf
PYSEC-2023-228
Oct 25, 2023
Command Injection in pip when used with Mercurial
Medium
Local
Low
Low
None
When installing a package from a Mercurial VCS URL, e.g. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 122 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
23.3
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
22.1b1
pre
7 CVEs
CVE-2026-13346
GHSA-qwm4-qh6w-59xr
PYSEC-2026-3721
Jul 29, 2026
pip would incorrectly handle doubly-encoded package URLs from indexes
Medium
Network
High
High
pip would incorrectly handle doubly-encoded package URLs from indexes allowing for files to be installed to arbitrary locations on disk even when installing wheels. This vulnerability requires downloading or installing a package from a malicious package index to succeed, malicious packages alone are not able to exploit this vulnerability. Note that this vulnerability only materially impacts users running Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 145 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
26.1
26.1.1
26.1.2
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.2.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-6357
PYSEC-2026-2876
GHSA-jp4c-xjxw-mgf9
Jul 13, 2026
pip Vulnerable to Inclusion of Functionality from Untrusted Control Sphere
Critical
Local
Low
High
pip prior to version 26.1 would run self-update check functionality after installing wheel files which required importing well-known Python modules names. These module imports were intentionally deferred to increase startup time of the pip CLI. The patch changes self-update functionality to run before wheels are installed to prevent newly-installed modules from being imported shortly after the installation of a wheel package. Users should still review package contents prior to installation. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 142 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-3219
PYSEC-2026-2875
GHSA-58qw-9mgm-455v
Jul 13, 2026
pip has an interpretation conflict due to handling both concatenated tar and ZIP files as ZIP files
Medium
Local
Low
None
pip handles concatenated tar and ZIP files as ZIP files regardless of filename or whether a file is both a tar and ZIP file. This behavior could result in confusing installation behavior, such as installing "incorrect" files according to the filename of the archive. New behavior only proceeds with installation if the file identifies uniquely as a ZIP or tar archive, not as both. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 142 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-1703
PYSEC-2026-1796
GHSA-6vgw-5pg2-w6jp
Jul 07, 2026
pip Path Traversal vulnerability
Medium
Network
Low
Low
When pip is installing and extracting a maliciously crafted wheel archive, files may be extracted outside the installation directory. The path traversal is limited to prefixes of the installation directory, thus isn't able to inject or overwrite executable files in typical situations. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 140 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-8869
PYSEC-2026-1795
GHSA-4xh5-x5gv-qwph
Jul 07, 2026
pip's fallback tar extraction doesn't check symbolic links point to extraction directory
High
Network
Low
None
When extracting a tar archive pip may not check symbolic links point into the extraction directory if the tarfile module doesn't implement PEP 706. Note that upgrading pip to a "fixed" version for this vulnerability doesn't fix all known vulnerabilities that are remediated by using a Python version that implements PEP 706. Note that this is a vulnerability in pip's fallback implementation of tar extraction for Python versions that don't implement PEP 706 and therefore are not secure to all vulnerabilities in the Python 'tarfile' module. If you're using a Python version that implements PEP 706 then pip doesn't use the "vulnerable" fallback code. Mitigations include upgrading to a version of pip that includes the fix, upgrading to a Python version that implements PEP 706 (Python >=3.9.17, >=3.10.12, >=3.11.4, or >=3.12), applying the linked patch, or inspecting source distributions (sdists) before installation as is already a best-practice. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 139 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
25.3
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-8643
GHSA-wf93-45jw-7689
PYSEC-2026-196
Jun 01, 2026
pip: Path traversal in console_scripts/gui_scripts entry point names allows installing scripts outside of target directory
Medium
Local
Low
Low
pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 144 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
26.1
26.1.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.1.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-5752
GHSA-mq26-g339-26xf
PYSEC-2023-228
Oct 25, 2023
Command Injection in pip when used with Mercurial
Medium
Local
Low
Low
None
When installing a package from a Mercurial VCS URL, e.g. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 122 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
23.3
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
22.0.4
patch
7 CVEs
CVE-2026-13346
GHSA-qwm4-qh6w-59xr
PYSEC-2026-3721
Jul 29, 2026
pip would incorrectly handle doubly-encoded package URLs from indexes
Medium
Network
High
High
pip would incorrectly handle doubly-encoded package URLs from indexes allowing for files to be installed to arbitrary locations on disk even when installing wheels. This vulnerability requires downloading or installing a package from a malicious package index to succeed, malicious packages alone are not able to exploit this vulnerability. Note that this vulnerability only materially impacts users running Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 145 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
26.1
26.1.1
26.1.2
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.2.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-6357
PYSEC-2026-2876
GHSA-jp4c-xjxw-mgf9
Jul 13, 2026
pip Vulnerable to Inclusion of Functionality from Untrusted Control Sphere
Critical
Local
Low
High
pip prior to version 26.1 would run self-update check functionality after installing wheel files which required importing well-known Python modules names. These module imports were intentionally deferred to increase startup time of the pip CLI. The patch changes self-update functionality to run before wheels are installed to prevent newly-installed modules from being imported shortly after the installation of a wheel package. Users should still review package contents prior to installation. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 142 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-3219
PYSEC-2026-2875
GHSA-58qw-9mgm-455v
Jul 13, 2026
pip has an interpretation conflict due to handling both concatenated tar and ZIP files as ZIP files
Medium
Local
Low
None
pip handles concatenated tar and ZIP files as ZIP files regardless of filename or whether a file is both a tar and ZIP file. This behavior could result in confusing installation behavior, such as installing "incorrect" files according to the filename of the archive. New behavior only proceeds with installation if the file identifies uniquely as a ZIP or tar archive, not as both. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 142 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-1703
PYSEC-2026-1796
GHSA-6vgw-5pg2-w6jp
Jul 07, 2026
pip Path Traversal vulnerability
Medium
Network
Low
Low
When pip is installing and extracting a maliciously crafted wheel archive, files may be extracted outside the installation directory. The path traversal is limited to prefixes of the installation directory, thus isn't able to inject or overwrite executable files in typical situations. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 140 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-8869
PYSEC-2026-1795
GHSA-4xh5-x5gv-qwph
Jul 07, 2026
pip's fallback tar extraction doesn't check symbolic links point to extraction directory
High
Network
Low
None
When extracting a tar archive pip may not check symbolic links point into the extraction directory if the tarfile module doesn't implement PEP 706. Note that upgrading pip to a "fixed" version for this vulnerability doesn't fix all known vulnerabilities that are remediated by using a Python version that implements PEP 706. Note that this is a vulnerability in pip's fallback implementation of tar extraction for Python versions that don't implement PEP 706 and therefore are not secure to all vulnerabilities in the Python 'tarfile' module. If you're using a Python version that implements PEP 706 then pip doesn't use the "vulnerable" fallback code. Mitigations include upgrading to a version of pip that includes the fix, upgrading to a Python version that implements PEP 706 (Python >=3.9.17, >=3.10.12, >=3.11.4, or >=3.12), applying the linked patch, or inspecting source distributions (sdists) before installation as is already a best-practice. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 139 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
25.3
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-8643
GHSA-wf93-45jw-7689
PYSEC-2026-196
Jun 01, 2026
pip: Path traversal in console_scripts/gui_scripts entry point names allows installing scripts outside of target directory
Medium
Local
Low
Low
pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 144 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
26.1
26.1.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.1.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-5752
GHSA-mq26-g339-26xf
PYSEC-2023-228
Oct 25, 2023
Command Injection in pip when used with Mercurial
Medium
Local
Low
Low
None
When installing a package from a Mercurial VCS URL, e.g. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 122 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
23.3
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
22.0.3
patch
7 CVEs
CVE-2026-13346
GHSA-qwm4-qh6w-59xr
PYSEC-2026-3721
Jul 29, 2026
pip would incorrectly handle doubly-encoded package URLs from indexes
Medium
Network
High
High
pip would incorrectly handle doubly-encoded package URLs from indexes allowing for files to be installed to arbitrary locations on disk even when installing wheels. This vulnerability requires downloading or installing a package from a malicious package index to succeed, malicious packages alone are not able to exploit this vulnerability. Note that this vulnerability only materially impacts users running Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 145 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
26.1
26.1.1
26.1.2
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.2.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-6357
PYSEC-2026-2876
GHSA-jp4c-xjxw-mgf9
Jul 13, 2026
pip Vulnerable to Inclusion of Functionality from Untrusted Control Sphere
Critical
Local
Low
High
pip prior to version 26.1 would run self-update check functionality after installing wheel files which required importing well-known Python modules names. These module imports were intentionally deferred to increase startup time of the pip CLI. The patch changes self-update functionality to run before wheels are installed to prevent newly-installed modules from being imported shortly after the installation of a wheel package. Users should still review package contents prior to installation. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 142 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-3219
PYSEC-2026-2875
GHSA-58qw-9mgm-455v
Jul 13, 2026
pip has an interpretation conflict due to handling both concatenated tar and ZIP files as ZIP files
Medium
Local
Low
None
pip handles concatenated tar and ZIP files as ZIP files regardless of filename or whether a file is both a tar and ZIP file. This behavior could result in confusing installation behavior, such as installing "incorrect" files according to the filename of the archive. New behavior only proceeds with installation if the file identifies uniquely as a ZIP or tar archive, not as both. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 142 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-1703
PYSEC-2026-1796
GHSA-6vgw-5pg2-w6jp
Jul 07, 2026
pip Path Traversal vulnerability
Medium
Network
Low
Low
When pip is installing and extracting a maliciously crafted wheel archive, files may be extracted outside the installation directory. The path traversal is limited to prefixes of the installation directory, thus isn't able to inject or overwrite executable files in typical situations. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 140 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-8869
PYSEC-2026-1795
GHSA-4xh5-x5gv-qwph
Jul 07, 2026
pip's fallback tar extraction doesn't check symbolic links point to extraction directory
High
Network
Low
None
When extracting a tar archive pip may not check symbolic links point into the extraction directory if the tarfile module doesn't implement PEP 706. Note that upgrading pip to a "fixed" version for this vulnerability doesn't fix all known vulnerabilities that are remediated by using a Python version that implements PEP 706. Note that this is a vulnerability in pip's fallback implementation of tar extraction for Python versions that don't implement PEP 706 and therefore are not secure to all vulnerabilities in the Python 'tarfile' module. If you're using a Python version that implements PEP 706 then pip doesn't use the "vulnerable" fallback code. Mitigations include upgrading to a version of pip that includes the fix, upgrading to a Python version that implements PEP 706 (Python >=3.9.17, >=3.10.12, >=3.11.4, or >=3.12), applying the linked patch, or inspecting source distributions (sdists) before installation as is already a best-practice. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 139 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
25.3
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-8643
GHSA-wf93-45jw-7689
PYSEC-2026-196
Jun 01, 2026
pip: Path traversal in console_scripts/gui_scripts entry point names allows installing scripts outside of target directory
Medium
Local
Low
Low
pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 144 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
26.1
26.1.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.1.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-5752
GHSA-mq26-g339-26xf
PYSEC-2023-228
Oct 25, 2023
Command Injection in pip when used with Mercurial
Medium
Local
Low
Low
None
When installing a package from a Mercurial VCS URL, e.g. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 122 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
23.3
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
22.0.2
patch
7 CVEs
CVE-2026-13346
GHSA-qwm4-qh6w-59xr
PYSEC-2026-3721
Jul 29, 2026
pip would incorrectly handle doubly-encoded package URLs from indexes
Medium
Network
High
High
pip would incorrectly handle doubly-encoded package URLs from indexes allowing for files to be installed to arbitrary locations on disk even when installing wheels. This vulnerability requires downloading or installing a package from a malicious package index to succeed, malicious packages alone are not able to exploit this vulnerability. Note that this vulnerability only materially impacts users running Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 145 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
26.1
26.1.1
26.1.2
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.2.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-6357
PYSEC-2026-2876
GHSA-jp4c-xjxw-mgf9
Jul 13, 2026
pip Vulnerable to Inclusion of Functionality from Untrusted Control Sphere
Critical
Local
Low
High
pip prior to version 26.1 would run self-update check functionality after installing wheel files which required importing well-known Python modules names. These module imports were intentionally deferred to increase startup time of the pip CLI. The patch changes self-update functionality to run before wheels are installed to prevent newly-installed modules from being imported shortly after the installation of a wheel package. Users should still review package contents prior to installation. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 142 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-3219
PYSEC-2026-2875
GHSA-58qw-9mgm-455v
Jul 13, 2026
pip has an interpretation conflict due to handling both concatenated tar and ZIP files as ZIP files
Medium
Local
Low
None
pip handles concatenated tar and ZIP files as ZIP files regardless of filename or whether a file is both a tar and ZIP file. This behavior could result in confusing installation behavior, such as installing "incorrect" files according to the filename of the archive. New behavior only proceeds with installation if the file identifies uniquely as a ZIP or tar archive, not as both. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 142 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-1703
PYSEC-2026-1796
GHSA-6vgw-5pg2-w6jp
Jul 07, 2026
pip Path Traversal vulnerability
Medium
Network
Low
Low
When pip is installing and extracting a maliciously crafted wheel archive, files may be extracted outside the installation directory. The path traversal is limited to prefixes of the installation directory, thus isn't able to inject or overwrite executable files in typical situations. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 140 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-8869
PYSEC-2026-1795
GHSA-4xh5-x5gv-qwph
Jul 07, 2026
pip's fallback tar extraction doesn't check symbolic links point to extraction directory
High
Network
Low
None
When extracting a tar archive pip may not check symbolic links point into the extraction directory if the tarfile module doesn't implement PEP 706. Note that upgrading pip to a "fixed" version for this vulnerability doesn't fix all known vulnerabilities that are remediated by using a Python version that implements PEP 706. Note that this is a vulnerability in pip's fallback implementation of tar extraction for Python versions that don't implement PEP 706 and therefore are not secure to all vulnerabilities in the Python 'tarfile' module. If you're using a Python version that implements PEP 706 then pip doesn't use the "vulnerable" fallback code. Mitigations include upgrading to a version of pip that includes the fix, upgrading to a Python version that implements PEP 706 (Python >=3.9.17, >=3.10.12, >=3.11.4, or >=3.12), applying the linked patch, or inspecting source distributions (sdists) before installation as is already a best-practice. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 139 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
25.3
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-8643
GHSA-wf93-45jw-7689
PYSEC-2026-196
Jun 01, 2026
pip: Path traversal in console_scripts/gui_scripts entry point names allows installing scripts outside of target directory
Medium
Local
Low
Low
pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 144 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
26.1
26.1.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.1.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-5752
GHSA-mq26-g339-26xf
PYSEC-2023-228
Oct 25, 2023
Command Injection in pip when used with Mercurial
Medium
Local
Low
Low
None
When installing a package from a Mercurial VCS URL, e.g. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 122 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
23.3
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
22.0.1
patch
7 CVEs
CVE-2026-13346
GHSA-qwm4-qh6w-59xr
PYSEC-2026-3721
Jul 29, 2026
pip would incorrectly handle doubly-encoded package URLs from indexes
Medium
Network
High
High
pip would incorrectly handle doubly-encoded package URLs from indexes allowing for files to be installed to arbitrary locations on disk even when installing wheels. This vulnerability requires downloading or installing a package from a malicious package index to succeed, malicious packages alone are not able to exploit this vulnerability. Note that this vulnerability only materially impacts users running Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 145 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
26.1
26.1.1
26.1.2
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.2.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-6357
PYSEC-2026-2876
GHSA-jp4c-xjxw-mgf9
Jul 13, 2026
pip Vulnerable to Inclusion of Functionality from Untrusted Control Sphere
Critical
Local
Low
High
pip prior to version 26.1 would run self-update check functionality after installing wheel files which required importing well-known Python modules names. These module imports were intentionally deferred to increase startup time of the pip CLI. The patch changes self-update functionality to run before wheels are installed to prevent newly-installed modules from being imported shortly after the installation of a wheel package. Users should still review package contents prior to installation. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 142 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-3219
PYSEC-2026-2875
GHSA-58qw-9mgm-455v
Jul 13, 2026
pip has an interpretation conflict due to handling both concatenated tar and ZIP files as ZIP files
Medium
Local
Low
None
pip handles concatenated tar and ZIP files as ZIP files regardless of filename or whether a file is both a tar and ZIP file. This behavior could result in confusing installation behavior, such as installing "incorrect" files according to the filename of the archive. New behavior only proceeds with installation if the file identifies uniquely as a ZIP or tar archive, not as both. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 142 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-1703
PYSEC-2026-1796
GHSA-6vgw-5pg2-w6jp
Jul 07, 2026
pip Path Traversal vulnerability
Medium
Network
Low
Low
When pip is installing and extracting a maliciously crafted wheel archive, files may be extracted outside the installation directory. The path traversal is limited to prefixes of the installation directory, thus isn't able to inject or overwrite executable files in typical situations. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 140 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-8869
PYSEC-2026-1795
GHSA-4xh5-x5gv-qwph
Jul 07, 2026
pip's fallback tar extraction doesn't check symbolic links point to extraction directory
High
Network
Low
None
When extracting a tar archive pip may not check symbolic links point into the extraction directory if the tarfile module doesn't implement PEP 706. Note that upgrading pip to a "fixed" version for this vulnerability doesn't fix all known vulnerabilities that are remediated by using a Python version that implements PEP 706. Note that this is a vulnerability in pip's fallback implementation of tar extraction for Python versions that don't implement PEP 706 and therefore are not secure to all vulnerabilities in the Python 'tarfile' module. If you're using a Python version that implements PEP 706 then pip doesn't use the "vulnerable" fallback code. Mitigations include upgrading to a version of pip that includes the fix, upgrading to a Python version that implements PEP 706 (Python >=3.9.17, >=3.10.12, >=3.11.4, or >=3.12), applying the linked patch, or inspecting source distributions (sdists) before installation as is already a best-practice. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 139 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
25.3
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-8643
GHSA-wf93-45jw-7689
PYSEC-2026-196
Jun 01, 2026
pip: Path traversal in console_scripts/gui_scripts entry point names allows installing scripts outside of target directory
Medium
Local
Low
Low
pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 144 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
26.1
26.1.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.1.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-5752
GHSA-mq26-g339-26xf
PYSEC-2023-228
Oct 25, 2023
Command Injection in pip when used with Mercurial
Medium
Local
Low
Low
None
When installing a package from a Mercurial VCS URL, e.g. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 122 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
23.3
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
22.0
major
7 CVEs
CVE-2026-13346
GHSA-qwm4-qh6w-59xr
PYSEC-2026-3721
Jul 29, 2026
pip would incorrectly handle doubly-encoded package URLs from indexes
Medium
Network
High
High
pip would incorrectly handle doubly-encoded package URLs from indexes allowing for files to be installed to arbitrary locations on disk even when installing wheels. This vulnerability requires downloading or installing a package from a malicious package index to succeed, malicious packages alone are not able to exploit this vulnerability. Note that this vulnerability only materially impacts users running Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 145 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
26.1
26.1.1
26.1.2
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.2.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-6357
PYSEC-2026-2876
GHSA-jp4c-xjxw-mgf9
Jul 13, 2026
pip Vulnerable to Inclusion of Functionality from Untrusted Control Sphere
Critical
Local
Low
High
pip prior to version 26.1 would run self-update check functionality after installing wheel files which required importing well-known Python modules names. These module imports were intentionally deferred to increase startup time of the pip CLI. The patch changes self-update functionality to run before wheels are installed to prevent newly-installed modules from being imported shortly after the installation of a wheel package. Users should still review package contents prior to installation. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 142 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-3219
PYSEC-2026-2875
GHSA-58qw-9mgm-455v
Jul 13, 2026
pip has an interpretation conflict due to handling both concatenated tar and ZIP files as ZIP files
Medium
Local
Low
None
pip handles concatenated tar and ZIP files as ZIP files regardless of filename or whether a file is both a tar and ZIP file. This behavior could result in confusing installation behavior, such as installing "incorrect" files according to the filename of the archive. New behavior only proceeds with installation if the file identifies uniquely as a ZIP or tar archive, not as both. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 142 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-1703
PYSEC-2026-1796
GHSA-6vgw-5pg2-w6jp
Jul 07, 2026
pip Path Traversal vulnerability
Medium
Network
Low
Low
When pip is installing and extracting a maliciously crafted wheel archive, files may be extracted outside the installation directory. The path traversal is limited to prefixes of the installation directory, thus isn't able to inject or overwrite executable files in typical situations. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 140 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-8869
PYSEC-2026-1795
GHSA-4xh5-x5gv-qwph
Jul 07, 2026
pip's fallback tar extraction doesn't check symbolic links point to extraction directory
High
Network
Low
None
When extracting a tar archive pip may not check symbolic links point into the extraction directory if the tarfile module doesn't implement PEP 706. Note that upgrading pip to a "fixed" version for this vulnerability doesn't fix all known vulnerabilities that are remediated by using a Python version that implements PEP 706. Note that this is a vulnerability in pip's fallback implementation of tar extraction for Python versions that don't implement PEP 706 and therefore are not secure to all vulnerabilities in the Python 'tarfile' module. If you're using a Python version that implements PEP 706 then pip doesn't use the "vulnerable" fallback code. Mitigations include upgrading to a version of pip that includes the fix, upgrading to a Python version that implements PEP 706 (Python >=3.9.17, >=3.10.12, >=3.11.4, or >=3.12), applying the linked patch, or inspecting source distributions (sdists) before installation as is already a best-practice. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 139 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
25.3
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-8643
GHSA-wf93-45jw-7689
PYSEC-2026-196
Jun 01, 2026
pip: Path traversal in console_scripts/gui_scripts entry point names allows installing scripts outside of target directory
Medium
Local
Low
Low
pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 144 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
26.1
26.1.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.1.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-5752
GHSA-mq26-g339-26xf
PYSEC-2023-228
Oct 25, 2023
Command Injection in pip when used with Mercurial
Medium
Local
Low
Low
None
When installing a package from a Mercurial VCS URL, e.g. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 122 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
23.3
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
21.3.1
patch
7 CVEs
CVE-2026-13346
GHSA-qwm4-qh6w-59xr
PYSEC-2026-3721
Jul 29, 2026
pip would incorrectly handle doubly-encoded package URLs from indexes
Medium
Network
High
High
pip would incorrectly handle doubly-encoded package URLs from indexes allowing for files to be installed to arbitrary locations on disk even when installing wheels. This vulnerability requires downloading or installing a package from a malicious package index to succeed, malicious packages alone are not able to exploit this vulnerability. Note that this vulnerability only materially impacts users running Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 145 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
26.1
26.1.1
26.1.2
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.2.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-6357
PYSEC-2026-2876
GHSA-jp4c-xjxw-mgf9
Jul 13, 2026
pip Vulnerable to Inclusion of Functionality from Untrusted Control Sphere
Critical
Local
Low
High
pip prior to version 26.1 would run self-update check functionality after installing wheel files which required importing well-known Python modules names. These module imports were intentionally deferred to increase startup time of the pip CLI. The patch changes self-update functionality to run before wheels are installed to prevent newly-installed modules from being imported shortly after the installation of a wheel package. Users should still review package contents prior to installation. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 142 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-3219
PYSEC-2026-2875
GHSA-58qw-9mgm-455v
Jul 13, 2026
pip has an interpretation conflict due to handling both concatenated tar and ZIP files as ZIP files
Medium
Local
Low
None
pip handles concatenated tar and ZIP files as ZIP files regardless of filename or whether a file is both a tar and ZIP file. This behavior could result in confusing installation behavior, such as installing "incorrect" files according to the filename of the archive. New behavior only proceeds with installation if the file identifies uniquely as a ZIP or tar archive, not as both. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 142 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-1703
PYSEC-2026-1796
GHSA-6vgw-5pg2-w6jp
Jul 07, 2026
pip Path Traversal vulnerability
Medium
Network
Low
Low
When pip is installing and extracting a maliciously crafted wheel archive, files may be extracted outside the installation directory. The path traversal is limited to prefixes of the installation directory, thus isn't able to inject or overwrite executable files in typical situations. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 140 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-8869
PYSEC-2026-1795
GHSA-4xh5-x5gv-qwph
Jul 07, 2026
pip's fallback tar extraction doesn't check symbolic links point to extraction directory
High
Network
Low
None
When extracting a tar archive pip may not check symbolic links point into the extraction directory if the tarfile module doesn't implement PEP 706. Note that upgrading pip to a "fixed" version for this vulnerability doesn't fix all known vulnerabilities that are remediated by using a Python version that implements PEP 706. Note that this is a vulnerability in pip's fallback implementation of tar extraction for Python versions that don't implement PEP 706 and therefore are not secure to all vulnerabilities in the Python 'tarfile' module. If you're using a Python version that implements PEP 706 then pip doesn't use the "vulnerable" fallback code. Mitigations include upgrading to a version of pip that includes the fix, upgrading to a Python version that implements PEP 706 (Python >=3.9.17, >=3.10.12, >=3.11.4, or >=3.12), applying the linked patch, or inspecting source distributions (sdists) before installation as is already a best-practice. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 139 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
25.3
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-8643
GHSA-wf93-45jw-7689
PYSEC-2026-196
Jun 01, 2026
pip: Path traversal in console_scripts/gui_scripts entry point names allows installing scripts outside of target directory
Medium
Local
Low
Low
pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 144 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
26.1
26.1.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.1.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-5752
GHSA-mq26-g339-26xf
PYSEC-2023-228
Oct 25, 2023
Command Injection in pip when used with Mercurial
Medium
Local
Low
Low
None
When installing a package from a Mercurial VCS URL, e.g. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 122 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
23.3
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
21.3
minor
7 CVEs
CVE-2026-13346
GHSA-qwm4-qh6w-59xr
PYSEC-2026-3721
Jul 29, 2026
pip would incorrectly handle doubly-encoded package URLs from indexes
Medium
Network
High
High
pip would incorrectly handle doubly-encoded package URLs from indexes allowing for files to be installed to arbitrary locations on disk even when installing wheels. This vulnerability requires downloading or installing a package from a malicious package index to succeed, malicious packages alone are not able to exploit this vulnerability. Note that this vulnerability only materially impacts users running Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 145 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
26.1
26.1.1
26.1.2
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.2.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-6357
PYSEC-2026-2876
GHSA-jp4c-xjxw-mgf9
Jul 13, 2026
pip Vulnerable to Inclusion of Functionality from Untrusted Control Sphere
Critical
Local
Low
High
pip prior to version 26.1 would run self-update check functionality after installing wheel files which required importing well-known Python modules names. These module imports were intentionally deferred to increase startup time of the pip CLI. The patch changes self-update functionality to run before wheels are installed to prevent newly-installed modules from being imported shortly after the installation of a wheel package. Users should still review package contents prior to installation. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 142 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-3219
PYSEC-2026-2875
GHSA-58qw-9mgm-455v
Jul 13, 2026
pip has an interpretation conflict due to handling both concatenated tar and ZIP files as ZIP files
Medium
Local
Low
None
pip handles concatenated tar and ZIP files as ZIP files regardless of filename or whether a file is both a tar and ZIP file. This behavior could result in confusing installation behavior, such as installing "incorrect" files according to the filename of the archive. New behavior only proceeds with installation if the file identifies uniquely as a ZIP or tar archive, not as both. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 142 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-1703
PYSEC-2026-1796
GHSA-6vgw-5pg2-w6jp
Jul 07, 2026
pip Path Traversal vulnerability
Medium
Network
Low
Low
When pip is installing and extracting a maliciously crafted wheel archive, files may be extracted outside the installation directory. The path traversal is limited to prefixes of the installation directory, thus isn't able to inject or overwrite executable files in typical situations. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 140 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-8869
PYSEC-2026-1795
GHSA-4xh5-x5gv-qwph
Jul 07, 2026
pip's fallback tar extraction doesn't check symbolic links point to extraction directory
High
Network
Low
None
When extracting a tar archive pip may not check symbolic links point into the extraction directory if the tarfile module doesn't implement PEP 706. Note that upgrading pip to a "fixed" version for this vulnerability doesn't fix all known vulnerabilities that are remediated by using a Python version that implements PEP 706. Note that this is a vulnerability in pip's fallback implementation of tar extraction for Python versions that don't implement PEP 706 and therefore are not secure to all vulnerabilities in the Python 'tarfile' module. If you're using a Python version that implements PEP 706 then pip doesn't use the "vulnerable" fallback code. Mitigations include upgrading to a version of pip that includes the fix, upgrading to a Python version that implements PEP 706 (Python >=3.9.17, >=3.10.12, >=3.11.4, or >=3.12), applying the linked patch, or inspecting source distributions (sdists) before installation as is already a best-practice. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 139 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
25.3
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-8643
GHSA-wf93-45jw-7689
PYSEC-2026-196
Jun 01, 2026
pip: Path traversal in console_scripts/gui_scripts entry point names allows installing scripts outside of target directory
Medium
Local
Low
Low
pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 144 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
26.1
26.1.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.1.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-5752
GHSA-mq26-g339-26xf
PYSEC-2023-228
Oct 25, 2023
Command Injection in pip when used with Mercurial
Medium
Local
Low
Low
None
When installing a package from a Mercurial VCS URL, e.g. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 122 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
23.3
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
21.2.4
patch
7 CVEs
CVE-2026-13346
GHSA-qwm4-qh6w-59xr
PYSEC-2026-3721
Jul 29, 2026
pip would incorrectly handle doubly-encoded package URLs from indexes
Medium
Network
High
High
pip would incorrectly handle doubly-encoded package URLs from indexes allowing for files to be installed to arbitrary locations on disk even when installing wheels. This vulnerability requires downloading or installing a package from a malicious package index to succeed, malicious packages alone are not able to exploit this vulnerability. Note that this vulnerability only materially impacts users running Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 145 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
26.1
26.1.1
26.1.2
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.2.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-6357
PYSEC-2026-2876
GHSA-jp4c-xjxw-mgf9
Jul 13, 2026
pip Vulnerable to Inclusion of Functionality from Untrusted Control Sphere
Critical
Local
Low
High
pip prior to version 26.1 would run self-update check functionality after installing wheel files which required importing well-known Python modules names. These module imports were intentionally deferred to increase startup time of the pip CLI. The patch changes self-update functionality to run before wheels are installed to prevent newly-installed modules from being imported shortly after the installation of a wheel package. Users should still review package contents prior to installation. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 142 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-3219
PYSEC-2026-2875
GHSA-58qw-9mgm-455v
Jul 13, 2026
pip has an interpretation conflict due to handling both concatenated tar and ZIP files as ZIP files
Medium
Local
Low
None
pip handles concatenated tar and ZIP files as ZIP files regardless of filename or whether a file is both a tar and ZIP file. This behavior could result in confusing installation behavior, such as installing "incorrect" files according to the filename of the archive. New behavior only proceeds with installation if the file identifies uniquely as a ZIP or tar archive, not as both. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 142 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-1703
PYSEC-2026-1796
GHSA-6vgw-5pg2-w6jp
Jul 07, 2026
pip Path Traversal vulnerability
Medium
Network
Low
Low
When pip is installing and extracting a maliciously crafted wheel archive, files may be extracted outside the installation directory. The path traversal is limited to prefixes of the installation directory, thus isn't able to inject or overwrite executable files in typical situations. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 140 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-8869
PYSEC-2026-1795
GHSA-4xh5-x5gv-qwph
Jul 07, 2026
pip's fallback tar extraction doesn't check symbolic links point to extraction directory
High
Network
Low
None
When extracting a tar archive pip may not check symbolic links point into the extraction directory if the tarfile module doesn't implement PEP 706. Note that upgrading pip to a "fixed" version for this vulnerability doesn't fix all known vulnerabilities that are remediated by using a Python version that implements PEP 706. Note that this is a vulnerability in pip's fallback implementation of tar extraction for Python versions that don't implement PEP 706 and therefore are not secure to all vulnerabilities in the Python 'tarfile' module. If you're using a Python version that implements PEP 706 then pip doesn't use the "vulnerable" fallback code. Mitigations include upgrading to a version of pip that includes the fix, upgrading to a Python version that implements PEP 706 (Python >=3.9.17, >=3.10.12, >=3.11.4, or >=3.12), applying the linked patch, or inspecting source distributions (sdists) before installation as is already a best-practice. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 139 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
25.3
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-8643
GHSA-wf93-45jw-7689
PYSEC-2026-196
Jun 01, 2026
pip: Path traversal in console_scripts/gui_scripts entry point names allows installing scripts outside of target directory
Medium
Local
Low
Low
pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 144 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
26.1
26.1.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.1.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-5752
GHSA-mq26-g339-26xf
PYSEC-2023-228
Oct 25, 2023
Command Injection in pip when used with Mercurial
Medium
Local
Low
Low
None
When installing a package from a Mercurial VCS URL, e.g. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 122 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
23.3
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
21.2.3
patch
7 CVEs
CVE-2026-13346
GHSA-qwm4-qh6w-59xr
PYSEC-2026-3721
Jul 29, 2026
pip would incorrectly handle doubly-encoded package URLs from indexes
Medium
Network
High
High
pip would incorrectly handle doubly-encoded package URLs from indexes allowing for files to be installed to arbitrary locations on disk even when installing wheels. This vulnerability requires downloading or installing a package from a malicious package index to succeed, malicious packages alone are not able to exploit this vulnerability. Note that this vulnerability only materially impacts users running Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 145 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
26.1
26.1.1
26.1.2
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.2.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-6357
PYSEC-2026-2876
GHSA-jp4c-xjxw-mgf9
Jul 13, 2026
pip Vulnerable to Inclusion of Functionality from Untrusted Control Sphere
Critical
Local
Low
High
pip prior to version 26.1 would run self-update check functionality after installing wheel files which required importing well-known Python modules names. These module imports were intentionally deferred to increase startup time of the pip CLI. The patch changes self-update functionality to run before wheels are installed to prevent newly-installed modules from being imported shortly after the installation of a wheel package. Users should still review package contents prior to installation. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 142 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-3219
PYSEC-2026-2875
GHSA-58qw-9mgm-455v
Jul 13, 2026
pip has an interpretation conflict due to handling both concatenated tar and ZIP files as ZIP files
Medium
Local
Low
None
pip handles concatenated tar and ZIP files as ZIP files regardless of filename or whether a file is both a tar and ZIP file. This behavior could result in confusing installation behavior, such as installing "incorrect" files according to the filename of the archive. New behavior only proceeds with installation if the file identifies uniquely as a ZIP or tar archive, not as both. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 142 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-1703
PYSEC-2026-1796
GHSA-6vgw-5pg2-w6jp
Jul 07, 2026
pip Path Traversal vulnerability
Medium
Network
Low
Low
When pip is installing and extracting a maliciously crafted wheel archive, files may be extracted outside the installation directory. The path traversal is limited to prefixes of the installation directory, thus isn't able to inject or overwrite executable files in typical situations. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 140 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-8869
PYSEC-2026-1795
GHSA-4xh5-x5gv-qwph
Jul 07, 2026
pip's fallback tar extraction doesn't check symbolic links point to extraction directory
High
Network
Low
None
When extracting a tar archive pip may not check symbolic links point into the extraction directory if the tarfile module doesn't implement PEP 706. Note that upgrading pip to a "fixed" version for this vulnerability doesn't fix all known vulnerabilities that are remediated by using a Python version that implements PEP 706. Note that this is a vulnerability in pip's fallback implementation of tar extraction for Python versions that don't implement PEP 706 and therefore are not secure to all vulnerabilities in the Python 'tarfile' module. If you're using a Python version that implements PEP 706 then pip doesn't use the "vulnerable" fallback code. Mitigations include upgrading to a version of pip that includes the fix, upgrading to a Python version that implements PEP 706 (Python >=3.9.17, >=3.10.12, >=3.11.4, or >=3.12), applying the linked patch, or inspecting source distributions (sdists) before installation as is already a best-practice. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 139 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
25.3
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-8643
GHSA-wf93-45jw-7689
PYSEC-2026-196
Jun 01, 2026
pip: Path traversal in console_scripts/gui_scripts entry point names allows installing scripts outside of target directory
Medium
Local
Low
Low
pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 144 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.0
24.1
24.1.1
24.1.2
24.1b1
24.1b2
24.2
24.3
24.3.1
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.0
26.0.1
26.1
26.1.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
26.1.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-5752
GHSA-mq26-g339-26xf
PYSEC-2023-228
Oct 25, 2023
Command Injection in pip when used with Mercurial
Medium
Local
Low
Low
None
When installing a package from a Mercurial VCS URL, e.g. Affected versions
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
+ 122 more Show less
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
10.0.0
10.0.0b1
10.0.0b2
10.0.1
18.0
18.1
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.0
20.0.1
20.0.2
20.1
20.1.1
20.1b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.2b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
20.3b1
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1
22.1.1
22.1.2
22.1b1
22.2
22.2.1
22.2.2
22.3
22.3.1
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.0.0
9.0.1
9.0.2
9.0.3
Fixed in
23.3
References
Updated Sep 10, 2026 · Source: OSV.dev |