PT-2026-33775 · Pypi · Pip

Published

2026-04-20

·

Updated

2026-06-12

·

CVE-2026-3219

CVSS v3.1

5.0

Medium

VectorAV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions pip (affected versions not specified)
Description pip processes concatenated tar and ZIP files exclusively as ZIP files, ignoring the filename or the fact that the file contains both archive types. This behavior can lead to the installation of incorrect files based on the archive's filename.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CLEANSTART-2026-SY44974
CVE-2026-3219
ECHO-E9F8-2DCB-3BE1
GHSA-58QW-9MGM-455V
OESA-2026-2360
OESA-2026-2361
OESA-2026-2362
OESA-2026-2363
OESA-2026-2497
OPENSUSE-SU-2026:10645-1
RHSA-2026:20074
SUSE-SU-2026:22018-1
SUSE-SU-2026:2387-1

Affected Products

Pip