virtualenv
Virtual Python Environment builder
Activity
- Latest release
- 5d ago
- Total releases
- 279
- Cadence
- ~4 days
- Last 12 months
- 40
Reach
- Stars
- 5.0k
Details
- License
- MIT
- First release
- Sep 14, 2007
| Version | Released | |
|---|---|---|
21.7.9
patch
| ||
21.7.8
patch
| ||
21.7.7
patch
| ||
21.7.6
patch
| ||
21.7.5
patch
| ||
21.7.4
patch
| ||
21.7.3
patch
| ||
21.7.2
patch
| ||
21.7.1
patch
| ||
21.7.0
minor
| ||
21.6.1
patch
| ||
21.6.0
minor
| ||
21.5.2
patch
| ||
21.5.1
patch
| ||
21.5.0
minor
| ||
21.4.3
patch
| ||
21.4.2
patch
| ||
21.4.1
patch
| ||
21.4.0
minor
| ||
21.3.3
patch
| ||
21.3.2
patch
| ||
21.3.1
patch
| ||
21.3.0
minor
| ||
21.2.4
patch
| ||
21.2.3
patch
| ||
21.2.2
patch
| ||
21.2.1
patch
| ||
21.2.0
minor
| ||
21.1.0
minor
| ||
21.0.0
major
| ||
20.39.1
patch
| ||
20.39.0
minor
| ||
20.38.0
minor
| ||
20.36.1
patch
| ||
20.36.0
minor
1 CVE
CVE-2026-22702
PYSEC-2026-2009
BIT-virtualenv-2026-22702
GHSA-597g-3phw-6986
Jul 07, 2026
virtualenv Has TOCTOU Vulnerabilities in Directory Creation
4.5
/ 10
Medium
Local
High
Low
None
Unchanged
Low
Low
Low
ImpactTOCTOU (Time-of-Check-Time-of-Use) vulnerabilities in Affected versions: All versions up to and including 20.36.1 Affected users: Any user running Attack scenarios:
PatchesThe vulnerability has been patched by replacing check-then-act patterns with atomic Fixed in: PR #3013 Versions with the fix: 20.36.2 and later Users should upgrade to version 20.36.2 or later. WorkaroundsIf you cannot upgrade immediately:
References
Affected versions
0.8
0.8.1
0.8.2
0.8.3
0.8.4
0.9
0.9.1
0.9.2
1.0
1.1
1.10
1.10.1
+ 233 more Show less
1.11
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.11.6
1.2
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.4rc1
1.5
1.5.1
1.5.2
1.6
1.6.1
1.6.2
1.6.3
1.6.4
1.7
1.7.1
1.7.1.1
1.7.1.2
1.7.2
1.8
1.8.1
1.8.2
1.8.3
1.8.4
1.9
1.9.1
12.0
12.0.1
12.0.2
12.0.4
12.0.5
12.0.6
12.0.7
12.1.0
12.1.1
13.0.0
13.0.1
13.0.2
13.0.3
13.1.0
13.1.1
13.1.2
14.0.0
14.0.1
14.0.2
14.0.3
14.0.4
14.0.5
14.0.6
15.0.0
15.0.1
15.0.2
15.0.3
15.1.0
15.2.0
16.0.0
16.1.0
16.2.0
16.3.0
16.3.1.dev0
16.4.0
16.4.1
16.4.3
16.4.4.dev0
16.5.0
16.6.0
16.6.1
16.6.2
16.7.0
16.7.1
16.7.10
16.7.11
16.7.12
16.7.2
16.7.3
16.7.4
16.7.5
16.7.6
16.7.7
16.7.8
16.7.9
20.0.0
20.0.0b1
20.0.0b2
20.0.1
20.0.10
20.0.11
20.0.12
20.0.13
20.0.14
20.0.15
20.0.16
20.0.17
20.0.18
20.0.19
20.0.2
20.0.20
20.0.21
20.0.22
20.0.23
20.0.24
20.0.25
20.0.26
20.0.27
20.0.28
20.0.29
20.0.3
20.0.30
20.0.31
20.0.32
20.0.33
20.0.34
20.0.35
20.0.4
20.0.5
20.0.6
20.0.7
20.0.8
20.0.9
20.1.0
20.10.0
20.11.0
20.11.1
20.11.2
20.12.0
20.12.1
20.13.0
20.13.1
20.13.2
20.13.3
20.13.4
20.14.0
20.14.1
20.15.0
20.15.1
20.16.0
20.16.1
20.16.2
20.16.3
20.16.4
20.16.5
20.16.6
20.16.7
20.17.0
20.17.1
20.18.0
20.19.0
20.2.0
20.2.1
20.2.2
20.20.0
20.21.0
20.21.1
20.22.0
20.23.0
20.23.1
20.24.0
20.24.1
20.24.2
20.24.3
20.24.4
20.24.5
20.24.6
20.24.7
20.25.0
20.25.1
20.25.2
20.25.3
20.26.0
20.26.1
20.26.2
20.26.3
20.26.4
20.26.5
20.26.6
20.27.0
20.27.1
20.28.0
20.28.1
20.29.0
20.29.1
20.29.2
20.29.3
20.3.0
20.3.1
20.30.0
20.31.0
20.31.1
20.31.2
20.32.0
20.33.0
20.33.1
20.34.0
20.35.0
20.35.1
20.35.2
20.35.3
20.35.4
20.36.0
20.4.0
20.4.1
20.4.2
20.4.3
20.4.4
20.4.5
20.4.6
20.4.7
20.5.0
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
20.8.1
20.9.0
Fixed in
20.36.1
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
20.35.4
patch
1 CVE
CVE-2026-22702
PYSEC-2026-2009
BIT-virtualenv-2026-22702
GHSA-597g-3phw-6986
Jul 07, 2026
virtualenv Has TOCTOU Vulnerabilities in Directory Creation
4.5
/ 10
Medium
Local
High
Low
None
Unchanged
Low
Low
Low
ImpactTOCTOU (Time-of-Check-Time-of-Use) vulnerabilities in Affected versions: All versions up to and including 20.36.1 Affected users: Any user running Attack scenarios:
PatchesThe vulnerability has been patched by replacing check-then-act patterns with atomic Fixed in: PR #3013 Versions with the fix: 20.36.2 and later Users should upgrade to version 20.36.2 or later. WorkaroundsIf you cannot upgrade immediately:
References
Affected versions
0.8
0.8.1
0.8.2
0.8.3
0.8.4
0.9
0.9.1
0.9.2
1.0
1.1
1.10
1.10.1
+ 233 more Show less
1.11
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.11.6
1.2
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.4rc1
1.5
1.5.1
1.5.2
1.6
1.6.1
1.6.2
1.6.3
1.6.4
1.7
1.7.1
1.7.1.1
1.7.1.2
1.7.2
1.8
1.8.1
1.8.2
1.8.3
1.8.4
1.9
1.9.1
12.0
12.0.1
12.0.2
12.0.4
12.0.5
12.0.6
12.0.7
12.1.0
12.1.1
13.0.0
13.0.1
13.0.2
13.0.3
13.1.0
13.1.1
13.1.2
14.0.0
14.0.1
14.0.2
14.0.3
14.0.4
14.0.5
14.0.6
15.0.0
15.0.1
15.0.2
15.0.3
15.1.0
15.2.0
16.0.0
16.1.0
16.2.0
16.3.0
16.3.1.dev0
16.4.0
16.4.1
16.4.3
16.4.4.dev0
16.5.0
16.6.0
16.6.1
16.6.2
16.7.0
16.7.1
16.7.10
16.7.11
16.7.12
16.7.2
16.7.3
16.7.4
16.7.5
16.7.6
16.7.7
16.7.8
16.7.9
20.0.0
20.0.0b1
20.0.0b2
20.0.1
20.0.10
20.0.11
20.0.12
20.0.13
20.0.14
20.0.15
20.0.16
20.0.17
20.0.18
20.0.19
20.0.2
20.0.20
20.0.21
20.0.22
20.0.23
20.0.24
20.0.25
20.0.26
20.0.27
20.0.28
20.0.29
20.0.3
20.0.30
20.0.31
20.0.32
20.0.33
20.0.34
20.0.35
20.0.4
20.0.5
20.0.6
20.0.7
20.0.8
20.0.9
20.1.0
20.10.0
20.11.0
20.11.1
20.11.2
20.12.0
20.12.1
20.13.0
20.13.1
20.13.2
20.13.3
20.13.4
20.14.0
20.14.1
20.15.0
20.15.1
20.16.0
20.16.1
20.16.2
20.16.3
20.16.4
20.16.5
20.16.6
20.16.7
20.17.0
20.17.1
20.18.0
20.19.0
20.2.0
20.2.1
20.2.2
20.20.0
20.21.0
20.21.1
20.22.0
20.23.0
20.23.1
20.24.0
20.24.1
20.24.2
20.24.3
20.24.4
20.24.5
20.24.6
20.24.7
20.25.0
20.25.1
20.25.2
20.25.3
20.26.0
20.26.1
20.26.2
20.26.3
20.26.4
20.26.5
20.26.6
20.27.0
20.27.1
20.28.0
20.28.1
20.29.0
20.29.1
20.29.2
20.29.3
20.3.0
20.3.1
20.30.0
20.31.0
20.31.1
20.31.2
20.32.0
20.33.0
20.33.1
20.34.0
20.35.0
20.35.1
20.35.2
20.35.3
20.35.4
20.36.0
20.4.0
20.4.1
20.4.2
20.4.3
20.4.4
20.4.5
20.4.6
20.4.7
20.5.0
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
20.8.1
20.9.0
Fixed in
20.36.1
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
20.35.3
patch
1 CVE
CVE-2026-22702
PYSEC-2026-2009
BIT-virtualenv-2026-22702
GHSA-597g-3phw-6986
Jul 07, 2026
virtualenv Has TOCTOU Vulnerabilities in Directory Creation
4.5
/ 10
Medium
Local
High
Low
None
Unchanged
Low
Low
Low
ImpactTOCTOU (Time-of-Check-Time-of-Use) vulnerabilities in Affected versions: All versions up to and including 20.36.1 Affected users: Any user running Attack scenarios:
PatchesThe vulnerability has been patched by replacing check-then-act patterns with atomic Fixed in: PR #3013 Versions with the fix: 20.36.2 and later Users should upgrade to version 20.36.2 or later. WorkaroundsIf you cannot upgrade immediately:
References
Affected versions
0.8
0.8.1
0.8.2
0.8.3
0.8.4
0.9
0.9.1
0.9.2
1.0
1.1
1.10
1.10.1
+ 233 more Show less
1.11
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.11.6
1.2
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.4rc1
1.5
1.5.1
1.5.2
1.6
1.6.1
1.6.2
1.6.3
1.6.4
1.7
1.7.1
1.7.1.1
1.7.1.2
1.7.2
1.8
1.8.1
1.8.2
1.8.3
1.8.4
1.9
1.9.1
12.0
12.0.1
12.0.2
12.0.4
12.0.5
12.0.6
12.0.7
12.1.0
12.1.1
13.0.0
13.0.1
13.0.2
13.0.3
13.1.0
13.1.1
13.1.2
14.0.0
14.0.1
14.0.2
14.0.3
14.0.4
14.0.5
14.0.6
15.0.0
15.0.1
15.0.2
15.0.3
15.1.0
15.2.0
16.0.0
16.1.0
16.2.0
16.3.0
16.3.1.dev0
16.4.0
16.4.1
16.4.3
16.4.4.dev0
16.5.0
16.6.0
16.6.1
16.6.2
16.7.0
16.7.1
16.7.10
16.7.11
16.7.12
16.7.2
16.7.3
16.7.4
16.7.5
16.7.6
16.7.7
16.7.8
16.7.9
20.0.0
20.0.0b1
20.0.0b2
20.0.1
20.0.10
20.0.11
20.0.12
20.0.13
20.0.14
20.0.15
20.0.16
20.0.17
20.0.18
20.0.19
20.0.2
20.0.20
20.0.21
20.0.22
20.0.23
20.0.24
20.0.25
20.0.26
20.0.27
20.0.28
20.0.29
20.0.3
20.0.30
20.0.31
20.0.32
20.0.33
20.0.34
20.0.35
20.0.4
20.0.5
20.0.6
20.0.7
20.0.8
20.0.9
20.1.0
20.10.0
20.11.0
20.11.1
20.11.2
20.12.0
20.12.1
20.13.0
20.13.1
20.13.2
20.13.3
20.13.4
20.14.0
20.14.1
20.15.0
20.15.1
20.16.0
20.16.1
20.16.2
20.16.3
20.16.4
20.16.5
20.16.6
20.16.7
20.17.0
20.17.1
20.18.0
20.19.0
20.2.0
20.2.1
20.2.2
20.20.0
20.21.0
20.21.1
20.22.0
20.23.0
20.23.1
20.24.0
20.24.1
20.24.2
20.24.3
20.24.4
20.24.5
20.24.6
20.24.7
20.25.0
20.25.1
20.25.2
20.25.3
20.26.0
20.26.1
20.26.2
20.26.3
20.26.4
20.26.5
20.26.6
20.27.0
20.27.1
20.28.0
20.28.1
20.29.0
20.29.1
20.29.2
20.29.3
20.3.0
20.3.1
20.30.0
20.31.0
20.31.1
20.31.2
20.32.0
20.33.0
20.33.1
20.34.0
20.35.0
20.35.1
20.35.2
20.35.3
20.35.4
20.36.0
20.4.0
20.4.1
20.4.2
20.4.3
20.4.4
20.4.5
20.4.6
20.4.7
20.5.0
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
20.8.1
20.9.0
Fixed in
20.36.1
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
20.35.2
patch
1 CVE
CVE-2026-22702
PYSEC-2026-2009
BIT-virtualenv-2026-22702
GHSA-597g-3phw-6986
Jul 07, 2026
virtualenv Has TOCTOU Vulnerabilities in Directory Creation
4.5
/ 10
Medium
Local
High
Low
None
Unchanged
Low
Low
Low
ImpactTOCTOU (Time-of-Check-Time-of-Use) vulnerabilities in Affected versions: All versions up to and including 20.36.1 Affected users: Any user running Attack scenarios:
PatchesThe vulnerability has been patched by replacing check-then-act patterns with atomic Fixed in: PR #3013 Versions with the fix: 20.36.2 and later Users should upgrade to version 20.36.2 or later. WorkaroundsIf you cannot upgrade immediately:
References
Affected versions
0.8
0.8.1
0.8.2
0.8.3
0.8.4
0.9
0.9.1
0.9.2
1.0
1.1
1.10
1.10.1
+ 233 more Show less
1.11
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.11.6
1.2
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.4rc1
1.5
1.5.1
1.5.2
1.6
1.6.1
1.6.2
1.6.3
1.6.4
1.7
1.7.1
1.7.1.1
1.7.1.2
1.7.2
1.8
1.8.1
1.8.2
1.8.3
1.8.4
1.9
1.9.1
12.0
12.0.1
12.0.2
12.0.4
12.0.5
12.0.6
12.0.7
12.1.0
12.1.1
13.0.0
13.0.1
13.0.2
13.0.3
13.1.0
13.1.1
13.1.2
14.0.0
14.0.1
14.0.2
14.0.3
14.0.4
14.0.5
14.0.6
15.0.0
15.0.1
15.0.2
15.0.3
15.1.0
15.2.0
16.0.0
16.1.0
16.2.0
16.3.0
16.3.1.dev0
16.4.0
16.4.1
16.4.3
16.4.4.dev0
16.5.0
16.6.0
16.6.1
16.6.2
16.7.0
16.7.1
16.7.10
16.7.11
16.7.12
16.7.2
16.7.3
16.7.4
16.7.5
16.7.6
16.7.7
16.7.8
16.7.9
20.0.0
20.0.0b1
20.0.0b2
20.0.1
20.0.10
20.0.11
20.0.12
20.0.13
20.0.14
20.0.15
20.0.16
20.0.17
20.0.18
20.0.19
20.0.2
20.0.20
20.0.21
20.0.22
20.0.23
20.0.24
20.0.25
20.0.26
20.0.27
20.0.28
20.0.29
20.0.3
20.0.30
20.0.31
20.0.32
20.0.33
20.0.34
20.0.35
20.0.4
20.0.5
20.0.6
20.0.7
20.0.8
20.0.9
20.1.0
20.10.0
20.11.0
20.11.1
20.11.2
20.12.0
20.12.1
20.13.0
20.13.1
20.13.2
20.13.3
20.13.4
20.14.0
20.14.1
20.15.0
20.15.1
20.16.0
20.16.1
20.16.2
20.16.3
20.16.4
20.16.5
20.16.6
20.16.7
20.17.0
20.17.1
20.18.0
20.19.0
20.2.0
20.2.1
20.2.2
20.20.0
20.21.0
20.21.1
20.22.0
20.23.0
20.23.1
20.24.0
20.24.1
20.24.2
20.24.3
20.24.4
20.24.5
20.24.6
20.24.7
20.25.0
20.25.1
20.25.2
20.25.3
20.26.0
20.26.1
20.26.2
20.26.3
20.26.4
20.26.5
20.26.6
20.27.0
20.27.1
20.28.0
20.28.1
20.29.0
20.29.1
20.29.2
20.29.3
20.3.0
20.3.1
20.30.0
20.31.0
20.31.1
20.31.2
20.32.0
20.33.0
20.33.1
20.34.0
20.35.0
20.35.1
20.35.2
20.35.3
20.35.4
20.36.0
20.4.0
20.4.1
20.4.2
20.4.3
20.4.4
20.4.5
20.4.6
20.4.7
20.5.0
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
20.8.1
20.9.0
Fixed in
20.36.1
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
20.35.1
patch
1 CVE
CVE-2026-22702
PYSEC-2026-2009
BIT-virtualenv-2026-22702
GHSA-597g-3phw-6986
Jul 07, 2026
virtualenv Has TOCTOU Vulnerabilities in Directory Creation
4.5
/ 10
Medium
Local
High
Low
None
Unchanged
Low
Low
Low
ImpactTOCTOU (Time-of-Check-Time-of-Use) vulnerabilities in Affected versions: All versions up to and including 20.36.1 Affected users: Any user running Attack scenarios:
PatchesThe vulnerability has been patched by replacing check-then-act patterns with atomic Fixed in: PR #3013 Versions with the fix: 20.36.2 and later Users should upgrade to version 20.36.2 or later. WorkaroundsIf you cannot upgrade immediately:
References
Affected versions
0.8
0.8.1
0.8.2
0.8.3
0.8.4
0.9
0.9.1
0.9.2
1.0
1.1
1.10
1.10.1
+ 233 more Show less
1.11
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.11.6
1.2
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.4rc1
1.5
1.5.1
1.5.2
1.6
1.6.1
1.6.2
1.6.3
1.6.4
1.7
1.7.1
1.7.1.1
1.7.1.2
1.7.2
1.8
1.8.1
1.8.2
1.8.3
1.8.4
1.9
1.9.1
12.0
12.0.1
12.0.2
12.0.4
12.0.5
12.0.6
12.0.7
12.1.0
12.1.1
13.0.0
13.0.1
13.0.2
13.0.3
13.1.0
13.1.1
13.1.2
14.0.0
14.0.1
14.0.2
14.0.3
14.0.4
14.0.5
14.0.6
15.0.0
15.0.1
15.0.2
15.0.3
15.1.0
15.2.0
16.0.0
16.1.0
16.2.0
16.3.0
16.3.1.dev0
16.4.0
16.4.1
16.4.3
16.4.4.dev0
16.5.0
16.6.0
16.6.1
16.6.2
16.7.0
16.7.1
16.7.10
16.7.11
16.7.12
16.7.2
16.7.3
16.7.4
16.7.5
16.7.6
16.7.7
16.7.8
16.7.9
20.0.0
20.0.0b1
20.0.0b2
20.0.1
20.0.10
20.0.11
20.0.12
20.0.13
20.0.14
20.0.15
20.0.16
20.0.17
20.0.18
20.0.19
20.0.2
20.0.20
20.0.21
20.0.22
20.0.23
20.0.24
20.0.25
20.0.26
20.0.27
20.0.28
20.0.29
20.0.3
20.0.30
20.0.31
20.0.32
20.0.33
20.0.34
20.0.35
20.0.4
20.0.5
20.0.6
20.0.7
20.0.8
20.0.9
20.1.0
20.10.0
20.11.0
20.11.1
20.11.2
20.12.0
20.12.1
20.13.0
20.13.1
20.13.2
20.13.3
20.13.4
20.14.0
20.14.1
20.15.0
20.15.1
20.16.0
20.16.1
20.16.2
20.16.3
20.16.4
20.16.5
20.16.6
20.16.7
20.17.0
20.17.1
20.18.0
20.19.0
20.2.0
20.2.1
20.2.2
20.20.0
20.21.0
20.21.1
20.22.0
20.23.0
20.23.1
20.24.0
20.24.1
20.24.2
20.24.3
20.24.4
20.24.5
20.24.6
20.24.7
20.25.0
20.25.1
20.25.2
20.25.3
20.26.0
20.26.1
20.26.2
20.26.3
20.26.4
20.26.5
20.26.6
20.27.0
20.27.1
20.28.0
20.28.1
20.29.0
20.29.1
20.29.2
20.29.3
20.3.0
20.3.1
20.30.0
20.31.0
20.31.1
20.31.2
20.32.0
20.33.0
20.33.1
20.34.0
20.35.0
20.35.1
20.35.2
20.35.3
20.35.4
20.36.0
20.4.0
20.4.1
20.4.2
20.4.3
20.4.4
20.4.5
20.4.6
20.4.7
20.5.0
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
20.8.1
20.9.0
Fixed in
20.36.1
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
20.35.0
minor
1 CVE
CVE-2026-22702
PYSEC-2026-2009
BIT-virtualenv-2026-22702
GHSA-597g-3phw-6986
Jul 07, 2026
virtualenv Has TOCTOU Vulnerabilities in Directory Creation
4.5
/ 10
Medium
Local
High
Low
None
Unchanged
Low
Low
Low
ImpactTOCTOU (Time-of-Check-Time-of-Use) vulnerabilities in Affected versions: All versions up to and including 20.36.1 Affected users: Any user running Attack scenarios:
PatchesThe vulnerability has been patched by replacing check-then-act patterns with atomic Fixed in: PR #3013 Versions with the fix: 20.36.2 and later Users should upgrade to version 20.36.2 or later. WorkaroundsIf you cannot upgrade immediately:
References
Affected versions
0.8
0.8.1
0.8.2
0.8.3
0.8.4
0.9
0.9.1
0.9.2
1.0
1.1
1.10
1.10.1
+ 233 more Show less
1.11
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.11.6
1.2
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.4rc1
1.5
1.5.1
1.5.2
1.6
1.6.1
1.6.2
1.6.3
1.6.4
1.7
1.7.1
1.7.1.1
1.7.1.2
1.7.2
1.8
1.8.1
1.8.2
1.8.3
1.8.4
1.9
1.9.1
12.0
12.0.1
12.0.2
12.0.4
12.0.5
12.0.6
12.0.7
12.1.0
12.1.1
13.0.0
13.0.1
13.0.2
13.0.3
13.1.0
13.1.1
13.1.2
14.0.0
14.0.1
14.0.2
14.0.3
14.0.4
14.0.5
14.0.6
15.0.0
15.0.1
15.0.2
15.0.3
15.1.0
15.2.0
16.0.0
16.1.0
16.2.0
16.3.0
16.3.1.dev0
16.4.0
16.4.1
16.4.3
16.4.4.dev0
16.5.0
16.6.0
16.6.1
16.6.2
16.7.0
16.7.1
16.7.10
16.7.11
16.7.12
16.7.2
16.7.3
16.7.4
16.7.5
16.7.6
16.7.7
16.7.8
16.7.9
20.0.0
20.0.0b1
20.0.0b2
20.0.1
20.0.10
20.0.11
20.0.12
20.0.13
20.0.14
20.0.15
20.0.16
20.0.17
20.0.18
20.0.19
20.0.2
20.0.20
20.0.21
20.0.22
20.0.23
20.0.24
20.0.25
20.0.26
20.0.27
20.0.28
20.0.29
20.0.3
20.0.30
20.0.31
20.0.32
20.0.33
20.0.34
20.0.35
20.0.4
20.0.5
20.0.6
20.0.7
20.0.8
20.0.9
20.1.0
20.10.0
20.11.0
20.11.1
20.11.2
20.12.0
20.12.1
20.13.0
20.13.1
20.13.2
20.13.3
20.13.4
20.14.0
20.14.1
20.15.0
20.15.1
20.16.0
20.16.1
20.16.2
20.16.3
20.16.4
20.16.5
20.16.6
20.16.7
20.17.0
20.17.1
20.18.0
20.19.0
20.2.0
20.2.1
20.2.2
20.20.0
20.21.0
20.21.1
20.22.0
20.23.0
20.23.1
20.24.0
20.24.1
20.24.2
20.24.3
20.24.4
20.24.5
20.24.6
20.24.7
20.25.0
20.25.1
20.25.2
20.25.3
20.26.0
20.26.1
20.26.2
20.26.3
20.26.4
20.26.5
20.26.6
20.27.0
20.27.1
20.28.0
20.28.1
20.29.0
20.29.1
20.29.2
20.29.3
20.3.0
20.3.1
20.30.0
20.31.0
20.31.1
20.31.2
20.32.0
20.33.0
20.33.1
20.34.0
20.35.0
20.35.1
20.35.2
20.35.3
20.35.4
20.36.0
20.4.0
20.4.1
20.4.2
20.4.3
20.4.4
20.4.5
20.4.6
20.4.7
20.5.0
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
20.8.1
20.9.0
Fixed in
20.36.1
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
20.34.0
minor
1 CVE
CVE-2026-22702
PYSEC-2026-2009
BIT-virtualenv-2026-22702
GHSA-597g-3phw-6986
Jul 07, 2026
virtualenv Has TOCTOU Vulnerabilities in Directory Creation
4.5
/ 10
Medium
Local
High
Low
None
Unchanged
Low
Low
Low
ImpactTOCTOU (Time-of-Check-Time-of-Use) vulnerabilities in Affected versions: All versions up to and including 20.36.1 Affected users: Any user running Attack scenarios:
PatchesThe vulnerability has been patched by replacing check-then-act patterns with atomic Fixed in: PR #3013 Versions with the fix: 20.36.2 and later Users should upgrade to version 20.36.2 or later. WorkaroundsIf you cannot upgrade immediately:
References
Affected versions
0.8
0.8.1
0.8.2
0.8.3
0.8.4
0.9
0.9.1
0.9.2
1.0
1.1
1.10
1.10.1
+ 233 more Show less
1.11
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.11.6
1.2
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.4rc1
1.5
1.5.1
1.5.2
1.6
1.6.1
1.6.2
1.6.3
1.6.4
1.7
1.7.1
1.7.1.1
1.7.1.2
1.7.2
1.8
1.8.1
1.8.2
1.8.3
1.8.4
1.9
1.9.1
12.0
12.0.1
12.0.2
12.0.4
12.0.5
12.0.6
12.0.7
12.1.0
12.1.1
13.0.0
13.0.1
13.0.2
13.0.3
13.1.0
13.1.1
13.1.2
14.0.0
14.0.1
14.0.2
14.0.3
14.0.4
14.0.5
14.0.6
15.0.0
15.0.1
15.0.2
15.0.3
15.1.0
15.2.0
16.0.0
16.1.0
16.2.0
16.3.0
16.3.1.dev0
16.4.0
16.4.1
16.4.3
16.4.4.dev0
16.5.0
16.6.0
16.6.1
16.6.2
16.7.0
16.7.1
16.7.10
16.7.11
16.7.12
16.7.2
16.7.3
16.7.4
16.7.5
16.7.6
16.7.7
16.7.8
16.7.9
20.0.0
20.0.0b1
20.0.0b2
20.0.1
20.0.10
20.0.11
20.0.12
20.0.13
20.0.14
20.0.15
20.0.16
20.0.17
20.0.18
20.0.19
20.0.2
20.0.20
20.0.21
20.0.22
20.0.23
20.0.24
20.0.25
20.0.26
20.0.27
20.0.28
20.0.29
20.0.3
20.0.30
20.0.31
20.0.32
20.0.33
20.0.34
20.0.35
20.0.4
20.0.5
20.0.6
20.0.7
20.0.8
20.0.9
20.1.0
20.10.0
20.11.0
20.11.1
20.11.2
20.12.0
20.12.1
20.13.0
20.13.1
20.13.2
20.13.3
20.13.4
20.14.0
20.14.1
20.15.0
20.15.1
20.16.0
20.16.1
20.16.2
20.16.3
20.16.4
20.16.5
20.16.6
20.16.7
20.17.0
20.17.1
20.18.0
20.19.0
20.2.0
20.2.1
20.2.2
20.20.0
20.21.0
20.21.1
20.22.0
20.23.0
20.23.1
20.24.0
20.24.1
20.24.2
20.24.3
20.24.4
20.24.5
20.24.6
20.24.7
20.25.0
20.25.1
20.25.2
20.25.3
20.26.0
20.26.1
20.26.2
20.26.3
20.26.4
20.26.5
20.26.6
20.27.0
20.27.1
20.28.0
20.28.1
20.29.0
20.29.1
20.29.2
20.29.3
20.3.0
20.3.1
20.30.0
20.31.0
20.31.1
20.31.2
20.32.0
20.33.0
20.33.1
20.34.0
20.35.0
20.35.1
20.35.2
20.35.3
20.35.4
20.36.0
20.4.0
20.4.1
20.4.2
20.4.3
20.4.4
20.4.5
20.4.6
20.4.7
20.5.0
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
20.8.1
20.9.0
Fixed in
20.36.1
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
20.33.1
patch
1 CVE
CVE-2026-22702
PYSEC-2026-2009
BIT-virtualenv-2026-22702
GHSA-597g-3phw-6986
Jul 07, 2026
virtualenv Has TOCTOU Vulnerabilities in Directory Creation
4.5
/ 10
Medium
Local
High
Low
None
Unchanged
Low
Low
Low
ImpactTOCTOU (Time-of-Check-Time-of-Use) vulnerabilities in Affected versions: All versions up to and including 20.36.1 Affected users: Any user running Attack scenarios:
PatchesThe vulnerability has been patched by replacing check-then-act patterns with atomic Fixed in: PR #3013 Versions with the fix: 20.36.2 and later Users should upgrade to version 20.36.2 or later. WorkaroundsIf you cannot upgrade immediately:
References
Affected versions
0.8
0.8.1
0.8.2
0.8.3
0.8.4
0.9
0.9.1
0.9.2
1.0
1.1
1.10
1.10.1
+ 233 more Show less
1.11
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.11.6
1.2
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.4rc1
1.5
1.5.1
1.5.2
1.6
1.6.1
1.6.2
1.6.3
1.6.4
1.7
1.7.1
1.7.1.1
1.7.1.2
1.7.2
1.8
1.8.1
1.8.2
1.8.3
1.8.4
1.9
1.9.1
12.0
12.0.1
12.0.2
12.0.4
12.0.5
12.0.6
12.0.7
12.1.0
12.1.1
13.0.0
13.0.1
13.0.2
13.0.3
13.1.0
13.1.1
13.1.2
14.0.0
14.0.1
14.0.2
14.0.3
14.0.4
14.0.5
14.0.6
15.0.0
15.0.1
15.0.2
15.0.3
15.1.0
15.2.0
16.0.0
16.1.0
16.2.0
16.3.0
16.3.1.dev0
16.4.0
16.4.1
16.4.3
16.4.4.dev0
16.5.0
16.6.0
16.6.1
16.6.2
16.7.0
16.7.1
16.7.10
16.7.11
16.7.12
16.7.2
16.7.3
16.7.4
16.7.5
16.7.6
16.7.7
16.7.8
16.7.9
20.0.0
20.0.0b1
20.0.0b2
20.0.1
20.0.10
20.0.11
20.0.12
20.0.13
20.0.14
20.0.15
20.0.16
20.0.17
20.0.18
20.0.19
20.0.2
20.0.20
20.0.21
20.0.22
20.0.23
20.0.24
20.0.25
20.0.26
20.0.27
20.0.28
20.0.29
20.0.3
20.0.30
20.0.31
20.0.32
20.0.33
20.0.34
20.0.35
20.0.4
20.0.5
20.0.6
20.0.7
20.0.8
20.0.9
20.1.0
20.10.0
20.11.0
20.11.1
20.11.2
20.12.0
20.12.1
20.13.0
20.13.1
20.13.2
20.13.3
20.13.4
20.14.0
20.14.1
20.15.0
20.15.1
20.16.0
20.16.1
20.16.2
20.16.3
20.16.4
20.16.5
20.16.6
20.16.7
20.17.0
20.17.1
20.18.0
20.19.0
20.2.0
20.2.1
20.2.2
20.20.0
20.21.0
20.21.1
20.22.0
20.23.0
20.23.1
20.24.0
20.24.1
20.24.2
20.24.3
20.24.4
20.24.5
20.24.6
20.24.7
20.25.0
20.25.1
20.25.2
20.25.3
20.26.0
20.26.1
20.26.2
20.26.3
20.26.4
20.26.5
20.26.6
20.27.0
20.27.1
20.28.0
20.28.1
20.29.0
20.29.1
20.29.2
20.29.3
20.3.0
20.3.1
20.30.0
20.31.0
20.31.1
20.31.2
20.32.0
20.33.0
20.33.1
20.34.0
20.35.0
20.35.1
20.35.2
20.35.3
20.35.4
20.36.0
20.4.0
20.4.1
20.4.2
20.4.3
20.4.4
20.4.5
20.4.6
20.4.7
20.5.0
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
20.8.1
20.9.0
Fixed in
20.36.1
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
20.33.0
minor
1 CVE
CVE-2026-22702
PYSEC-2026-2009
BIT-virtualenv-2026-22702
GHSA-597g-3phw-6986
Jul 07, 2026
virtualenv Has TOCTOU Vulnerabilities in Directory Creation
4.5
/ 10
Medium
Local
High
Low
None
Unchanged
Low
Low
Low
ImpactTOCTOU (Time-of-Check-Time-of-Use) vulnerabilities in Affected versions: All versions up to and including 20.36.1 Affected users: Any user running Attack scenarios:
PatchesThe vulnerability has been patched by replacing check-then-act patterns with atomic Fixed in: PR #3013 Versions with the fix: 20.36.2 and later Users should upgrade to version 20.36.2 or later. WorkaroundsIf you cannot upgrade immediately:
References
Affected versions
0.8
0.8.1
0.8.2
0.8.3
0.8.4
0.9
0.9.1
0.9.2
1.0
1.1
1.10
1.10.1
+ 233 more Show less
1.11
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.11.6
1.2
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.4rc1
1.5
1.5.1
1.5.2
1.6
1.6.1
1.6.2
1.6.3
1.6.4
1.7
1.7.1
1.7.1.1
1.7.1.2
1.7.2
1.8
1.8.1
1.8.2
1.8.3
1.8.4
1.9
1.9.1
12.0
12.0.1
12.0.2
12.0.4
12.0.5
12.0.6
12.0.7
12.1.0
12.1.1
13.0.0
13.0.1
13.0.2
13.0.3
13.1.0
13.1.1
13.1.2
14.0.0
14.0.1
14.0.2
14.0.3
14.0.4
14.0.5
14.0.6
15.0.0
15.0.1
15.0.2
15.0.3
15.1.0
15.2.0
16.0.0
16.1.0
16.2.0
16.3.0
16.3.1.dev0
16.4.0
16.4.1
16.4.3
16.4.4.dev0
16.5.0
16.6.0
16.6.1
16.6.2
16.7.0
16.7.1
16.7.10
16.7.11
16.7.12
16.7.2
16.7.3
16.7.4
16.7.5
16.7.6
16.7.7
16.7.8
16.7.9
20.0.0
20.0.0b1
20.0.0b2
20.0.1
20.0.10
20.0.11
20.0.12
20.0.13
20.0.14
20.0.15
20.0.16
20.0.17
20.0.18
20.0.19
20.0.2
20.0.20
20.0.21
20.0.22
20.0.23
20.0.24
20.0.25
20.0.26
20.0.27
20.0.28
20.0.29
20.0.3
20.0.30
20.0.31
20.0.32
20.0.33
20.0.34
20.0.35
20.0.4
20.0.5
20.0.6
20.0.7
20.0.8
20.0.9
20.1.0
20.10.0
20.11.0
20.11.1
20.11.2
20.12.0
20.12.1
20.13.0
20.13.1
20.13.2
20.13.3
20.13.4
20.14.0
20.14.1
20.15.0
20.15.1
20.16.0
20.16.1
20.16.2
20.16.3
20.16.4
20.16.5
20.16.6
20.16.7
20.17.0
20.17.1
20.18.0
20.19.0
20.2.0
20.2.1
20.2.2
20.20.0
20.21.0
20.21.1
20.22.0
20.23.0
20.23.1
20.24.0
20.24.1
20.24.2
20.24.3
20.24.4
20.24.5
20.24.6
20.24.7
20.25.0
20.25.1
20.25.2
20.25.3
20.26.0
20.26.1
20.26.2
20.26.3
20.26.4
20.26.5
20.26.6
20.27.0
20.27.1
20.28.0
20.28.1
20.29.0
20.29.1
20.29.2
20.29.3
20.3.0
20.3.1
20.30.0
20.31.0
20.31.1
20.31.2
20.32.0
20.33.0
20.33.1
20.34.0
20.35.0
20.35.1
20.35.2
20.35.3
20.35.4
20.36.0
20.4.0
20.4.1
20.4.2
20.4.3
20.4.4
20.4.5
20.4.6
20.4.7
20.5.0
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
20.8.1
20.9.0
Fixed in
20.36.1
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
20.32.0
minor
1 CVE
CVE-2026-22702
PYSEC-2026-2009
BIT-virtualenv-2026-22702
GHSA-597g-3phw-6986
Jul 07, 2026
virtualenv Has TOCTOU Vulnerabilities in Directory Creation
4.5
/ 10
Medium
Local
High
Low
None
Unchanged
Low
Low
Low
ImpactTOCTOU (Time-of-Check-Time-of-Use) vulnerabilities in Affected versions: All versions up to and including 20.36.1 Affected users: Any user running Attack scenarios:
PatchesThe vulnerability has been patched by replacing check-then-act patterns with atomic Fixed in: PR #3013 Versions with the fix: 20.36.2 and later Users should upgrade to version 20.36.2 or later. WorkaroundsIf you cannot upgrade immediately:
References
Affected versions
0.8
0.8.1
0.8.2
0.8.3
0.8.4
0.9
0.9.1
0.9.2
1.0
1.1
1.10
1.10.1
+ 233 more Show less
1.11
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.11.6
1.2
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.4rc1
1.5
1.5.1
1.5.2
1.6
1.6.1
1.6.2
1.6.3
1.6.4
1.7
1.7.1
1.7.1.1
1.7.1.2
1.7.2
1.8
1.8.1
1.8.2
1.8.3
1.8.4
1.9
1.9.1
12.0
12.0.1
12.0.2
12.0.4
12.0.5
12.0.6
12.0.7
12.1.0
12.1.1
13.0.0
13.0.1
13.0.2
13.0.3
13.1.0
13.1.1
13.1.2
14.0.0
14.0.1
14.0.2
14.0.3
14.0.4
14.0.5
14.0.6
15.0.0
15.0.1
15.0.2
15.0.3
15.1.0
15.2.0
16.0.0
16.1.0
16.2.0
16.3.0
16.3.1.dev0
16.4.0
16.4.1
16.4.3
16.4.4.dev0
16.5.0
16.6.0
16.6.1
16.6.2
16.7.0
16.7.1
16.7.10
16.7.11
16.7.12
16.7.2
16.7.3
16.7.4
16.7.5
16.7.6
16.7.7
16.7.8
16.7.9
20.0.0
20.0.0b1
20.0.0b2
20.0.1
20.0.10
20.0.11
20.0.12
20.0.13
20.0.14
20.0.15
20.0.16
20.0.17
20.0.18
20.0.19
20.0.2
20.0.20
20.0.21
20.0.22
20.0.23
20.0.24
20.0.25
20.0.26
20.0.27
20.0.28
20.0.29
20.0.3
20.0.30
20.0.31
20.0.32
20.0.33
20.0.34
20.0.35
20.0.4
20.0.5
20.0.6
20.0.7
20.0.8
20.0.9
20.1.0
20.10.0
20.11.0
20.11.1
20.11.2
20.12.0
20.12.1
20.13.0
20.13.1
20.13.2
20.13.3
20.13.4
20.14.0
20.14.1
20.15.0
20.15.1
20.16.0
20.16.1
20.16.2
20.16.3
20.16.4
20.16.5
20.16.6
20.16.7
20.17.0
20.17.1
20.18.0
20.19.0
20.2.0
20.2.1
20.2.2
20.20.0
20.21.0
20.21.1
20.22.0
20.23.0
20.23.1
20.24.0
20.24.1
20.24.2
20.24.3
20.24.4
20.24.5
20.24.6
20.24.7
20.25.0
20.25.1
20.25.2
20.25.3
20.26.0
20.26.1
20.26.2
20.26.3
20.26.4
20.26.5
20.26.6
20.27.0
20.27.1
20.28.0
20.28.1
20.29.0
20.29.1
20.29.2
20.29.3
20.3.0
20.3.1
20.30.0
20.31.0
20.31.1
20.31.2
20.32.0
20.33.0
20.33.1
20.34.0
20.35.0
20.35.1
20.35.2
20.35.3
20.35.4
20.36.0
20.4.0
20.4.1
20.4.2
20.4.3
20.4.4
20.4.5
20.4.6
20.4.7
20.5.0
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
20.8.1
20.9.0
Fixed in
20.36.1
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
20.31.2
patch
1 CVE
CVE-2026-22702
PYSEC-2026-2009
BIT-virtualenv-2026-22702
GHSA-597g-3phw-6986
Jul 07, 2026
virtualenv Has TOCTOU Vulnerabilities in Directory Creation
4.5
/ 10
Medium
Local
High
Low
None
Unchanged
Low
Low
Low
ImpactTOCTOU (Time-of-Check-Time-of-Use) vulnerabilities in Affected versions: All versions up to and including 20.36.1 Affected users: Any user running Attack scenarios:
PatchesThe vulnerability has been patched by replacing check-then-act patterns with atomic Fixed in: PR #3013 Versions with the fix: 20.36.2 and later Users should upgrade to version 20.36.2 or later. WorkaroundsIf you cannot upgrade immediately:
References
Affected versions
0.8
0.8.1
0.8.2
0.8.3
0.8.4
0.9
0.9.1
0.9.2
1.0
1.1
1.10
1.10.1
+ 233 more Show less
1.11
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.11.6
1.2
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.4rc1
1.5
1.5.1
1.5.2
1.6
1.6.1
1.6.2
1.6.3
1.6.4
1.7
1.7.1
1.7.1.1
1.7.1.2
1.7.2
1.8
1.8.1
1.8.2
1.8.3
1.8.4
1.9
1.9.1
12.0
12.0.1
12.0.2
12.0.4
12.0.5
12.0.6
12.0.7
12.1.0
12.1.1
13.0.0
13.0.1
13.0.2
13.0.3
13.1.0
13.1.1
13.1.2
14.0.0
14.0.1
14.0.2
14.0.3
14.0.4
14.0.5
14.0.6
15.0.0
15.0.1
15.0.2
15.0.3
15.1.0
15.2.0
16.0.0
16.1.0
16.2.0
16.3.0
16.3.1.dev0
16.4.0
16.4.1
16.4.3
16.4.4.dev0
16.5.0
16.6.0
16.6.1
16.6.2
16.7.0
16.7.1
16.7.10
16.7.11
16.7.12
16.7.2
16.7.3
16.7.4
16.7.5
16.7.6
16.7.7
16.7.8
16.7.9
20.0.0
20.0.0b1
20.0.0b2
20.0.1
20.0.10
20.0.11
20.0.12
20.0.13
20.0.14
20.0.15
20.0.16
20.0.17
20.0.18
20.0.19
20.0.2
20.0.20
20.0.21
20.0.22
20.0.23
20.0.24
20.0.25
20.0.26
20.0.27
20.0.28
20.0.29
20.0.3
20.0.30
20.0.31
20.0.32
20.0.33
20.0.34
20.0.35
20.0.4
20.0.5
20.0.6
20.0.7
20.0.8
20.0.9
20.1.0
20.10.0
20.11.0
20.11.1
20.11.2
20.12.0
20.12.1
20.13.0
20.13.1
20.13.2
20.13.3
20.13.4
20.14.0
20.14.1
20.15.0
20.15.1
20.16.0
20.16.1
20.16.2
20.16.3
20.16.4
20.16.5
20.16.6
20.16.7
20.17.0
20.17.1
20.18.0
20.19.0
20.2.0
20.2.1
20.2.2
20.20.0
20.21.0
20.21.1
20.22.0
20.23.0
20.23.1
20.24.0
20.24.1
20.24.2
20.24.3
20.24.4
20.24.5
20.24.6
20.24.7
20.25.0
20.25.1
20.25.2
20.25.3
20.26.0
20.26.1
20.26.2
20.26.3
20.26.4
20.26.5
20.26.6
20.27.0
20.27.1
20.28.0
20.28.1
20.29.0
20.29.1
20.29.2
20.29.3
20.3.0
20.3.1
20.30.0
20.31.0
20.31.1
20.31.2
20.32.0
20.33.0
20.33.1
20.34.0
20.35.0
20.35.1
20.35.2
20.35.3
20.35.4
20.36.0
20.4.0
20.4.1
20.4.2
20.4.3
20.4.4
20.4.5
20.4.6
20.4.7
20.5.0
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
20.8.1
20.9.0
Fixed in
20.36.1
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
20.31.1
patch
1 CVE
CVE-2026-22702
PYSEC-2026-2009
BIT-virtualenv-2026-22702
GHSA-597g-3phw-6986
Jul 07, 2026
virtualenv Has TOCTOU Vulnerabilities in Directory Creation
4.5
/ 10
Medium
Local
High
Low
None
Unchanged
Low
Low
Low
ImpactTOCTOU (Time-of-Check-Time-of-Use) vulnerabilities in Affected versions: All versions up to and including 20.36.1 Affected users: Any user running Attack scenarios:
PatchesThe vulnerability has been patched by replacing check-then-act patterns with atomic Fixed in: PR #3013 Versions with the fix: 20.36.2 and later Users should upgrade to version 20.36.2 or later. WorkaroundsIf you cannot upgrade immediately:
References
Affected versions
0.8
0.8.1
0.8.2
0.8.3
0.8.4
0.9
0.9.1
0.9.2
1.0
1.1
1.10
1.10.1
+ 233 more Show less
1.11
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.11.6
1.2
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.4rc1
1.5
1.5.1
1.5.2
1.6
1.6.1
1.6.2
1.6.3
1.6.4
1.7
1.7.1
1.7.1.1
1.7.1.2
1.7.2
1.8
1.8.1
1.8.2
1.8.3
1.8.4
1.9
1.9.1
12.0
12.0.1
12.0.2
12.0.4
12.0.5
12.0.6
12.0.7
12.1.0
12.1.1
13.0.0
13.0.1
13.0.2
13.0.3
13.1.0
13.1.1
13.1.2
14.0.0
14.0.1
14.0.2
14.0.3
14.0.4
14.0.5
14.0.6
15.0.0
15.0.1
15.0.2
15.0.3
15.1.0
15.2.0
16.0.0
16.1.0
16.2.0
16.3.0
16.3.1.dev0
16.4.0
16.4.1
16.4.3
16.4.4.dev0
16.5.0
16.6.0
16.6.1
16.6.2
16.7.0
16.7.1
16.7.10
16.7.11
16.7.12
16.7.2
16.7.3
16.7.4
16.7.5
16.7.6
16.7.7
16.7.8
16.7.9
20.0.0
20.0.0b1
20.0.0b2
20.0.1
20.0.10
20.0.11
20.0.12
20.0.13
20.0.14
20.0.15
20.0.16
20.0.17
20.0.18
20.0.19
20.0.2
20.0.20
20.0.21
20.0.22
20.0.23
20.0.24
20.0.25
20.0.26
20.0.27
20.0.28
20.0.29
20.0.3
20.0.30
20.0.31
20.0.32
20.0.33
20.0.34
20.0.35
20.0.4
20.0.5
20.0.6
20.0.7
20.0.8
20.0.9
20.1.0
20.10.0
20.11.0
20.11.1
20.11.2
20.12.0
20.12.1
20.13.0
20.13.1
20.13.2
20.13.3
20.13.4
20.14.0
20.14.1
20.15.0
20.15.1
20.16.0
20.16.1
20.16.2
20.16.3
20.16.4
20.16.5
20.16.6
20.16.7
20.17.0
20.17.1
20.18.0
20.19.0
20.2.0
20.2.1
20.2.2
20.20.0
20.21.0
20.21.1
20.22.0
20.23.0
20.23.1
20.24.0
20.24.1
20.24.2
20.24.3
20.24.4
20.24.5
20.24.6
20.24.7
20.25.0
20.25.1
20.25.2
20.25.3
20.26.0
20.26.1
20.26.2
20.26.3
20.26.4
20.26.5
20.26.6
20.27.0
20.27.1
20.28.0
20.28.1
20.29.0
20.29.1
20.29.2
20.29.3
20.3.0
20.3.1
20.30.0
20.31.0
20.31.1
20.31.2
20.32.0
20.33.0
20.33.1
20.34.0
20.35.0
20.35.1
20.35.2
20.35.3
20.35.4
20.36.0
20.4.0
20.4.1
20.4.2
20.4.3
20.4.4
20.4.5
20.4.6
20.4.7
20.5.0
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
20.8.1
20.9.0
Fixed in
20.36.1
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
20.31.0
minor
1 CVE
CVE-2026-22702
PYSEC-2026-2009
BIT-virtualenv-2026-22702
GHSA-597g-3phw-6986
Jul 07, 2026
virtualenv Has TOCTOU Vulnerabilities in Directory Creation
4.5
/ 10
Medium
Local
High
Low
None
Unchanged
Low
Low
Low
ImpactTOCTOU (Time-of-Check-Time-of-Use) vulnerabilities in Affected versions: All versions up to and including 20.36.1 Affected users: Any user running Attack scenarios:
PatchesThe vulnerability has been patched by replacing check-then-act patterns with atomic Fixed in: PR #3013 Versions with the fix: 20.36.2 and later Users should upgrade to version 20.36.2 or later. WorkaroundsIf you cannot upgrade immediately:
References
Affected versions
0.8
0.8.1
0.8.2
0.8.3
0.8.4
0.9
0.9.1
0.9.2
1.0
1.1
1.10
1.10.1
+ 233 more Show less
1.11
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.11.6
1.2
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.4rc1
1.5
1.5.1
1.5.2
1.6
1.6.1
1.6.2
1.6.3
1.6.4
1.7
1.7.1
1.7.1.1
1.7.1.2
1.7.2
1.8
1.8.1
1.8.2
1.8.3
1.8.4
1.9
1.9.1
12.0
12.0.1
12.0.2
12.0.4
12.0.5
12.0.6
12.0.7
12.1.0
12.1.1
13.0.0
13.0.1
13.0.2
13.0.3
13.1.0
13.1.1
13.1.2
14.0.0
14.0.1
14.0.2
14.0.3
14.0.4
14.0.5
14.0.6
15.0.0
15.0.1
15.0.2
15.0.3
15.1.0
15.2.0
16.0.0
16.1.0
16.2.0
16.3.0
16.3.1.dev0
16.4.0
16.4.1
16.4.3
16.4.4.dev0
16.5.0
16.6.0
16.6.1
16.6.2
16.7.0
16.7.1
16.7.10
16.7.11
16.7.12
16.7.2
16.7.3
16.7.4
16.7.5
16.7.6
16.7.7
16.7.8
16.7.9
20.0.0
20.0.0b1
20.0.0b2
20.0.1
20.0.10
20.0.11
20.0.12
20.0.13
20.0.14
20.0.15
20.0.16
20.0.17
20.0.18
20.0.19
20.0.2
20.0.20
20.0.21
20.0.22
20.0.23
20.0.24
20.0.25
20.0.26
20.0.27
20.0.28
20.0.29
20.0.3
20.0.30
20.0.31
20.0.32
20.0.33
20.0.34
20.0.35
20.0.4
20.0.5
20.0.6
20.0.7
20.0.8
20.0.9
20.1.0
20.10.0
20.11.0
20.11.1
20.11.2
20.12.0
20.12.1
20.13.0
20.13.1
20.13.2
20.13.3
20.13.4
20.14.0
20.14.1
20.15.0
20.15.1
20.16.0
20.16.1
20.16.2
20.16.3
20.16.4
20.16.5
20.16.6
20.16.7
20.17.0
20.17.1
20.18.0
20.19.0
20.2.0
20.2.1
20.2.2
20.20.0
20.21.0
20.21.1
20.22.0
20.23.0
20.23.1
20.24.0
20.24.1
20.24.2
20.24.3
20.24.4
20.24.5
20.24.6
20.24.7
20.25.0
20.25.1
20.25.2
20.25.3
20.26.0
20.26.1
20.26.2
20.26.3
20.26.4
20.26.5
20.26.6
20.27.0
20.27.1
20.28.0
20.28.1
20.29.0
20.29.1
20.29.2
20.29.3
20.3.0
20.3.1
20.30.0
20.31.0
20.31.1
20.31.2
20.32.0
20.33.0
20.33.1
20.34.0
20.35.0
20.35.1
20.35.2
20.35.3
20.35.4
20.36.0
20.4.0
20.4.1
20.4.2
20.4.3
20.4.4
20.4.5
20.4.6
20.4.7
20.5.0
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
20.8.1
20.9.0
Fixed in
20.36.1
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
20.30.0
minor
1 CVE
CVE-2026-22702
PYSEC-2026-2009
BIT-virtualenv-2026-22702
GHSA-597g-3phw-6986
Jul 07, 2026
virtualenv Has TOCTOU Vulnerabilities in Directory Creation
4.5
/ 10
Medium
Local
High
Low
None
Unchanged
Low
Low
Low
ImpactTOCTOU (Time-of-Check-Time-of-Use) vulnerabilities in Affected versions: All versions up to and including 20.36.1 Affected users: Any user running Attack scenarios:
PatchesThe vulnerability has been patched by replacing check-then-act patterns with atomic Fixed in: PR #3013 Versions with the fix: 20.36.2 and later Users should upgrade to version 20.36.2 or later. WorkaroundsIf you cannot upgrade immediately:
References
Affected versions
0.8
0.8.1
0.8.2
0.8.3
0.8.4
0.9
0.9.1
0.9.2
1.0
1.1
1.10
1.10.1
+ 233 more Show less
1.11
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.11.6
1.2
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.4rc1
1.5
1.5.1
1.5.2
1.6
1.6.1
1.6.2
1.6.3
1.6.4
1.7
1.7.1
1.7.1.1
1.7.1.2
1.7.2
1.8
1.8.1
1.8.2
1.8.3
1.8.4
1.9
1.9.1
12.0
12.0.1
12.0.2
12.0.4
12.0.5
12.0.6
12.0.7
12.1.0
12.1.1
13.0.0
13.0.1
13.0.2
13.0.3
13.1.0
13.1.1
13.1.2
14.0.0
14.0.1
14.0.2
14.0.3
14.0.4
14.0.5
14.0.6
15.0.0
15.0.1
15.0.2
15.0.3
15.1.0
15.2.0
16.0.0
16.1.0
16.2.0
16.3.0
16.3.1.dev0
16.4.0
16.4.1
16.4.3
16.4.4.dev0
16.5.0
16.6.0
16.6.1
16.6.2
16.7.0
16.7.1
16.7.10
16.7.11
16.7.12
16.7.2
16.7.3
16.7.4
16.7.5
16.7.6
16.7.7
16.7.8
16.7.9
20.0.0
20.0.0b1
20.0.0b2
20.0.1
20.0.10
20.0.11
20.0.12
20.0.13
20.0.14
20.0.15
20.0.16
20.0.17
20.0.18
20.0.19
20.0.2
20.0.20
20.0.21
20.0.22
20.0.23
20.0.24
20.0.25
20.0.26
20.0.27
20.0.28
20.0.29
20.0.3
20.0.30
20.0.31
20.0.32
20.0.33
20.0.34
20.0.35
20.0.4
20.0.5
20.0.6
20.0.7
20.0.8
20.0.9
20.1.0
20.10.0
20.11.0
20.11.1
20.11.2
20.12.0
20.12.1
20.13.0
20.13.1
20.13.2
20.13.3
20.13.4
20.14.0
20.14.1
20.15.0
20.15.1
20.16.0
20.16.1
20.16.2
20.16.3
20.16.4
20.16.5
20.16.6
20.16.7
20.17.0
20.17.1
20.18.0
20.19.0
20.2.0
20.2.1
20.2.2
20.20.0
20.21.0
20.21.1
20.22.0
20.23.0
20.23.1
20.24.0
20.24.1
20.24.2
20.24.3
20.24.4
20.24.5
20.24.6
20.24.7
20.25.0
20.25.1
20.25.2
20.25.3
20.26.0
20.26.1
20.26.2
20.26.3
20.26.4
20.26.5
20.26.6
20.27.0
20.27.1
20.28.0
20.28.1
20.29.0
20.29.1
20.29.2
20.29.3
20.3.0
20.3.1
20.30.0
20.31.0
20.31.1
20.31.2
20.32.0
20.33.0
20.33.1
20.34.0
20.35.0
20.35.1
20.35.2
20.35.3
20.35.4
20.36.0
20.4.0
20.4.1
20.4.2
20.4.3
20.4.4
20.4.5
20.4.6
20.4.7
20.5.0
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
20.8.1
20.9.0
Fixed in
20.36.1
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
20.29.3
patch
1 CVE
CVE-2026-22702
PYSEC-2026-2009
BIT-virtualenv-2026-22702
GHSA-597g-3phw-6986
Jul 07, 2026
virtualenv Has TOCTOU Vulnerabilities in Directory Creation
4.5
/ 10
Medium
Local
High
Low
None
Unchanged
Low
Low
Low
ImpactTOCTOU (Time-of-Check-Time-of-Use) vulnerabilities in Affected versions: All versions up to and including 20.36.1 Affected users: Any user running Attack scenarios:
PatchesThe vulnerability has been patched by replacing check-then-act patterns with atomic Fixed in: PR #3013 Versions with the fix: 20.36.2 and later Users should upgrade to version 20.36.2 or later. WorkaroundsIf you cannot upgrade immediately:
References
Affected versions
0.8
0.8.1
0.8.2
0.8.3
0.8.4
0.9
0.9.1
0.9.2
1.0
1.1
1.10
1.10.1
+ 233 more Show less
1.11
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.11.6
1.2
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.4rc1
1.5
1.5.1
1.5.2
1.6
1.6.1
1.6.2
1.6.3
1.6.4
1.7
1.7.1
1.7.1.1
1.7.1.2
1.7.2
1.8
1.8.1
1.8.2
1.8.3
1.8.4
1.9
1.9.1
12.0
12.0.1
12.0.2
12.0.4
12.0.5
12.0.6
12.0.7
12.1.0
12.1.1
13.0.0
13.0.1
13.0.2
13.0.3
13.1.0
13.1.1
13.1.2
14.0.0
14.0.1
14.0.2
14.0.3
14.0.4
14.0.5
14.0.6
15.0.0
15.0.1
15.0.2
15.0.3
15.1.0
15.2.0
16.0.0
16.1.0
16.2.0
16.3.0
16.3.1.dev0
16.4.0
16.4.1
16.4.3
16.4.4.dev0
16.5.0
16.6.0
16.6.1
16.6.2
16.7.0
16.7.1
16.7.10
16.7.11
16.7.12
16.7.2
16.7.3
16.7.4
16.7.5
16.7.6
16.7.7
16.7.8
16.7.9
20.0.0
20.0.0b1
20.0.0b2
20.0.1
20.0.10
20.0.11
20.0.12
20.0.13
20.0.14
20.0.15
20.0.16
20.0.17
20.0.18
20.0.19
20.0.2
20.0.20
20.0.21
20.0.22
20.0.23
20.0.24
20.0.25
20.0.26
20.0.27
20.0.28
20.0.29
20.0.3
20.0.30
20.0.31
20.0.32
20.0.33
20.0.34
20.0.35
20.0.4
20.0.5
20.0.6
20.0.7
20.0.8
20.0.9
20.1.0
20.10.0
20.11.0
20.11.1
20.11.2
20.12.0
20.12.1
20.13.0
20.13.1
20.13.2
20.13.3
20.13.4
20.14.0
20.14.1
20.15.0
20.15.1
20.16.0
20.16.1
20.16.2
20.16.3
20.16.4
20.16.5
20.16.6
20.16.7
20.17.0
20.17.1
20.18.0
20.19.0
20.2.0
20.2.1
20.2.2
20.20.0
20.21.0
20.21.1
20.22.0
20.23.0
20.23.1
20.24.0
20.24.1
20.24.2
20.24.3
20.24.4
20.24.5
20.24.6
20.24.7
20.25.0
20.25.1
20.25.2
20.25.3
20.26.0
20.26.1
20.26.2
20.26.3
20.26.4
20.26.5
20.26.6
20.27.0
20.27.1
20.28.0
20.28.1
20.29.0
20.29.1
20.29.2
20.29.3
20.3.0
20.3.1
20.30.0
20.31.0
20.31.1
20.31.2
20.32.0
20.33.0
20.33.1
20.34.0
20.35.0
20.35.1
20.35.2
20.35.3
20.35.4
20.36.0
20.4.0
20.4.1
20.4.2
20.4.3
20.4.4
20.4.5
20.4.6
20.4.7
20.5.0
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
20.8.1
20.9.0
Fixed in
20.36.1
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
20.29.2
patch
1 CVE
CVE-2026-22702
PYSEC-2026-2009
BIT-virtualenv-2026-22702
GHSA-597g-3phw-6986
Jul 07, 2026
virtualenv Has TOCTOU Vulnerabilities in Directory Creation
4.5
/ 10
Medium
Local
High
Low
None
Unchanged
Low
Low
Low
ImpactTOCTOU (Time-of-Check-Time-of-Use) vulnerabilities in Affected versions: All versions up to and including 20.36.1 Affected users: Any user running Attack scenarios:
PatchesThe vulnerability has been patched by replacing check-then-act patterns with atomic Fixed in: PR #3013 Versions with the fix: 20.36.2 and later Users should upgrade to version 20.36.2 or later. WorkaroundsIf you cannot upgrade immediately:
References
Affected versions
0.8
0.8.1
0.8.2
0.8.3
0.8.4
0.9
0.9.1
0.9.2
1.0
1.1
1.10
1.10.1
+ 233 more Show less
1.11
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.11.6
1.2
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.4rc1
1.5
1.5.1
1.5.2
1.6
1.6.1
1.6.2
1.6.3
1.6.4
1.7
1.7.1
1.7.1.1
1.7.1.2
1.7.2
1.8
1.8.1
1.8.2
1.8.3
1.8.4
1.9
1.9.1
12.0
12.0.1
12.0.2
12.0.4
12.0.5
12.0.6
12.0.7
12.1.0
12.1.1
13.0.0
13.0.1
13.0.2
13.0.3
13.1.0
13.1.1
13.1.2
14.0.0
14.0.1
14.0.2
14.0.3
14.0.4
14.0.5
14.0.6
15.0.0
15.0.1
15.0.2
15.0.3
15.1.0
15.2.0
16.0.0
16.1.0
16.2.0
16.3.0
16.3.1.dev0
16.4.0
16.4.1
16.4.3
16.4.4.dev0
16.5.0
16.6.0
16.6.1
16.6.2
16.7.0
16.7.1
16.7.10
16.7.11
16.7.12
16.7.2
16.7.3
16.7.4
16.7.5
16.7.6
16.7.7
16.7.8
16.7.9
20.0.0
20.0.0b1
20.0.0b2
20.0.1
20.0.10
20.0.11
20.0.12
20.0.13
20.0.14
20.0.15
20.0.16
20.0.17
20.0.18
20.0.19
20.0.2
20.0.20
20.0.21
20.0.22
20.0.23
20.0.24
20.0.25
20.0.26
20.0.27
20.0.28
20.0.29
20.0.3
20.0.30
20.0.31
20.0.32
20.0.33
20.0.34
20.0.35
20.0.4
20.0.5
20.0.6
20.0.7
20.0.8
20.0.9
20.1.0
20.10.0
20.11.0
20.11.1
20.11.2
20.12.0
20.12.1
20.13.0
20.13.1
20.13.2
20.13.3
20.13.4
20.14.0
20.14.1
20.15.0
20.15.1
20.16.0
20.16.1
20.16.2
20.16.3
20.16.4
20.16.5
20.16.6
20.16.7
20.17.0
20.17.1
20.18.0
20.19.0
20.2.0
20.2.1
20.2.2
20.20.0
20.21.0
20.21.1
20.22.0
20.23.0
20.23.1
20.24.0
20.24.1
20.24.2
20.24.3
20.24.4
20.24.5
20.24.6
20.24.7
20.25.0
20.25.1
20.25.2
20.25.3
20.26.0
20.26.1
20.26.2
20.26.3
20.26.4
20.26.5
20.26.6
20.27.0
20.27.1
20.28.0
20.28.1
20.29.0
20.29.1
20.29.2
20.29.3
20.3.0
20.3.1
20.30.0
20.31.0
20.31.1
20.31.2
20.32.0
20.33.0
20.33.1
20.34.0
20.35.0
20.35.1
20.35.2
20.35.3
20.35.4
20.36.0
20.4.0
20.4.1
20.4.2
20.4.3
20.4.4
20.4.5
20.4.6
20.4.7
20.5.0
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
20.8.1
20.9.0
Fixed in
20.36.1
References
Updated Jul 07, 2026 · Source: OSV.dev |