Python Packaging Authority pip

5 known vulnerabilities in Python Packaging Authority pip, with patch priority, exploit likelihood and the news covering them.

Latest vulnerabilities

  • CVE-2026-13346 CVSS 5.6 medium pip would incorrectly handle doubly-encoded package URLs from indexes allowing for files to be installed to arbitrary locations on disk…
  • CVE-2026-8643 CVSS 4.1 medium pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the…
  • CVE-2026-3219 CVSS 4.6 medium pip handles concatenated tar and ZIP files as ZIP files regardless of filename or whether a file is both a tar and ZIP file. This behavior…
  • CVE-2026-1703 CVSS 2.0 low When pip is installing and extracting a maliciously crafted wheel archive, files may be extracted outside the installation directory. The…
  • CVE-2025-8869 CVSS 5.9 medium When extracting a tar archive pip may not check symbolic links point into the extraction directory if the tarfile module doesn't implement…