pip handles concatenated tar and ZIP files as ZIP files regardless of filename or whether a file is both a tar and ZIP file. This behavior could result in confusing installation behavior, such as installing "incorrect" files according to the filename of the archive. New behavior only proceeds with installation if the file identifies uniquely as a ZIP or tar archive, not as both.
CVSS Details
- CVSS 4.0 Base Score: 4.6 (MEDIUM)
- CVSS 4.0 Vector: (CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Redhat_linux | — | No solution exists | Jul 17, 2026 | Apr 20, 2026 |
| Suse | — | Upgrade python313-pipUpgrade python-xmlUpgrade python3-pipUpgrade python-demoUpgrade python-pipUpgrade python-develUpgrade python-tkUpgrade pythonUpgrade python-doc-pdfUpgrade libpython2_7-1_0-32bitUpgrade python-32bitUpgrade libpython2_7-1_0Upgrade python-idleUpgrade python-gdbmUpgrade python-cursesUpgrade python311-pipUpgrade python-docUpgrade python313-pip-wheelUpgrade python-base-32bitUpgrade python-base | Jun 4, 2026 | Jun 4, 2026 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jun 5, 2026 | Apr 20, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub