<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T16:55:13.870489+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2025:10407</id>
    <title>ALSA-2025:10407 — Moderate: python-setuptools security update</title>
    <updated>2026-10-02T16:55:14.063858+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:9: python3-setuptools, AlmaLinux:9: python3-setuptools-wheel</p>
<p>Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems.</p>
<p>Security Fix(es):</p>
<p>* setuptools: Path Traversal Vulnerability in setuptools PackageIndex (CVE-2025-47273)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2025:10407"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2025-08604</id>
    <title>bdu:2025-08604</title>
    <updated>2026-10-02T16:55:14.063950+00:00</updated>
    <content>bdu:2025-08604</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2025-08604"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2025-47273</id>
    <title>BELL-CVE-2025-47273</title>
    <updated>2026-10-02T16:55:14.063971+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: py3-setuptools, Alpaquita:stream: py3-setuptools, BellSoft Hardened Containers:23: py3-setuptools, BellSoft Hardened Containers:stream: py3-setuptools</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2025-47273"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-setuptools-2025-47273</id>
    <title>BIT-setuptools-2025-47273 — setuptools has a path traversal vulnerability in PackageIndex.download that leads to Arbitrary File Write</title>
    <updated>2026-10-02T16:55:14.063996+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: setuptools</p>
<p>setuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. A path traversal vulnerability in `PackageIndex` is present in setuptools prior to version 78.1.1. An attacker would be allowed to write files to arbitrary locations on the filesystem with the permissions of the process running the Python code, which could escalate to remote code execution depending on the context. Version 78.1.1 fixes the issue.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-setuptools-2025-47273"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-ansible-cve-2025-47273</id>
    <title>BREW-ansible-CVE-2025-47273 — setuptools has a path traversal vulnerability in PackageIndex.download that leads to Arbitrary File Write</title>
    <updated>2026-10-02T16:55:14.064018+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: ansible</p>
<p>### Summary 
A path traversal vulnerability in `PackageIndex` was fixed in setuptools version 78.1.1</p>
<p>### Details
```
    def _download_url(self, url, tmpdir):
        # Determine download filename
        #
        name, _fragment = egg_info_for_url(url)
        if name:
            while '..' in name:
                name = name.replace('..', '.').replace('\\', '_')
        else:
            name = "__downloaded__"  # default if URL has no path contents</p>
<p>if name.endswith('.[egg.zip](http://egg.zip/)'):
            name = name[:-4]  # strip the extra .zip before download</p>
<p>--&gt;       filename = os.path.join(tmpdir, name)
```</p>
<p>Here: https://github.com/pypa/setuptools/blob/6ead555c5fb29bc57fe6105b1bffc163f56fd558/setuptools/package_index.py#L810C1-L825C88</p>
<p>`os.path.join()` discards the first argument `tmpdir` if the second begins with a slash or drive letter.
`name` is derived from a URL without sufficient sanitization. While there is some attempt to sanitize by replacing instances of '..' with '.', it is insufficient.</p>
<p>### Risk Assessment
As easy_install and package_index are deprecated, the exploitation surface is reduced.
However, it seems this could be exploited in a similar fashion like https://github.com/advisories/GHSA-r9hx-vwmv-q579, and as described by POC 4 in https://github.com/advisories/GHSA-cx63-2mw6-8hw5 report: via malicious URLs present on the pages of a package index.</p>
<p>### Impact
An attacker would be allowed to write files to arbitrary locations on th…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-ansible-cve-2025-47273"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0693</id>
    <title>certfr-2025-avi-0693 — De multiples vulnérabilités ont été découvertes dans VMware Tanzu. Elles permettent à un attaquant de provoquer un prob…</title>
    <updated>2026-10-02T16:55:14.064063+00:00</updated>
    <content>certfr-2025-avi-0693</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2025-avi-0693"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-eq71754</id>
    <title>Withdrawn: CLEANSTART-2026-EQ71754 — Security fixes for CVE-2024-6345, CVE-2025-47273, CVE-2025-59375 applied in versions: 3.11.14-r0</title>
    <updated>2026-10-02T16:55:14.064079+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: python3</p>
<p>Multiple security vulnerabilities affect the python3 package. These issues are resolved in later releases. See references for individual vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-eq71754"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-241546</id>
    <title>EUVD-2026-241546</title>
    <updated>2026-10-02T16:55:14.064100+00:00</updated>
    <content>EUVD-2026-241546</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-241546"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-47273</id>
    <title>fkie_cve-2025-47273</title>
    <updated>2026-10-02T16:55:14.064112+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>setuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. A path traversal vulnerability in `PackageIndex` is present in setuptools prior to version 78.1.1. An attacker would be allowed to write files to arbitrary locations on the filesystem with the permissions of the process running the Python code, which could escalate to remote code execution depending on the context. Version 78.1.1 fixes the issue.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-47273"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-5rjg-fvgr-3xxf</id>
    <title>GHSA-5rjg-fvgr-3xxf — setuptools has a path traversal vulnerability in PackageIndex.download that leads to Arbitrary File Write</title>
    <updated>2026-10-02T16:55:14.064133+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: setuptools</p>
<p>### Summary 
A path traversal vulnerability in `PackageIndex` was fixed in setuptools version 78.1.1</p>
<p>### Details
```
    def _download_url(self, url, tmpdir):
        # Determine download filename
        #
        name, _fragment = egg_info_for_url(url)
        if name:
            while '..' in name:
                name = name.replace('..', '.').replace('\\', '_')
        else:
            name = "__downloaded__"  # default if URL has no path contents</p>
<p>if name.endswith('.[egg.zip](http://egg.zip/)'):
            name = name[:-4]  # strip the extra .zip before download</p>
<p>--&gt;       filename = os.path.join(tmpdir, name)
```</p>
<p>Here: https://github.com/pypa/setuptools/blob/6ead555c5fb29bc57fe6105b1bffc163f56fd558/setuptools/package_index.py#L810C1-L825C88</p>
<p>`os.path.join()` discards the first argument `tmpdir` if the second begins with a slash or drive letter.
`name` is derived from a URL without sufficient sanitization. While there is some attempt to sanitize by replacing instances of '..' with '.', it is insufficient.</p>
<p>### Risk Assessment
As easy_install and package_index are deprecated, the exploitation surface is reduced.
However, it seems this could be exploited in a similar fashion like https://github.com/advisories/GHSA-r9hx-vwmv-q579, and as described by POC 4 in https://github.com/advisories/GHSA-cx63-2mw6-8hw5 report: via malicious URLs present on the pages of a package index.</p>
<p>### Impact
An attacker would be allowed to write files to arbitrary locations on th…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-5rjg-fvgr-3xxf"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2025-47273</id>
    <title>msrc_CVE-2025-47273 — setuptools has a path traversal vulnerability in PackageIndex.download that leads to Arbitrary File Write</title>
    <updated>2026-10-02T16:55:14.064171+00:00</updated>
    <content>msrc_CVE-2025-47273</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2025-47273"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-3376</id>
    <title>OESA-2026-3376 — python-setuptools security update</title>
    <updated>2026-10-02T16:55:14.064189+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:22.03-LTS-SP4: python-setuptools</p>
<p>Setuptools is a collection of enhancements to the Python distutils that allow you to more easily build and distribute Python packages, especially ones that have dependencies on other packages.

Security Fix(es):</p>
<p>setuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. A path traversal vulnerability in `PackageIndex` is present in setuptools prior to version 78.1.1. An attacker would be allowed to write files to arbitrary locations on the filesystem with the permissions of the process running the Python code, which could escalate to remote code execution depending on the context. Version 78.1.1 fixes the issue.(CVE-2025-47273)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-3376"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10539-1</id>
    <title>openSUSE-SU-2026:10539-1 — oci-cli-3.76.2-1.1 on GA media</title>
    <updated>2026-10-02T16:55:14.064213+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>oci-cli-3.76.2-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:10539-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2025-49</id>
    <title>PYSEC-2025-49</title>
    <updated>2026-10-02T16:55:14.064233+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: setuptools</p>
<p>setuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. A path traversal vulnerability in `PackageIndex` is present in setuptools prior to version 78.1.1. An attacker would be allowed to write files to arbitrary locations on the filesystem with the permissions of the process running the Python code, which could escalate to remote code execution depending on the context. Version 78.1.1 fixes the issue.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2025-49"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2025:10787</id>
    <title>RHSA-2025:10787 — Red Hat Security Advisory: Red Hat OpenShift Builds 1.4.1</title>
    <updated>2026-10-02T16:55:14.064252+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>setuptools: Path Traversal Vulnerability in setuptools PackageIndex</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2025:10787"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2025:01693-1</id>
    <title>SUSE-SU-2025:01693-1 — Security update for python36-setuptools</title>
    <updated>2026-10-02T16:55:14.064275+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for python36-setuptools</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2025:01693-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-47273</id>
    <title>UBUNTU-CVE-2025-47273</title>
    <updated>2026-10-02T16:55:14.064291+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: python-pip, Ubuntu:Pro:14.04:LTS: python-setuptools, Ubuntu:Pro:16.04:LTS: python-setuptools, Ubuntu:Pro:16.04:LTS: python-pip, Ubuntu:Pro:18.04:LTS: python-setuptools, Ubuntu:Pro:18.04:LTS: python-pip, Ubuntu:20.04:LTS: setuptools, Ubuntu:22.04:LTS: setuptools, Ubuntu:Pro:22.04:LTS: python-setuptools, Ubuntu:24.04:LTS: setuptools</p>
<p>setuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. A path traversal vulnerability in `PackageIndex` is present in setuptools prior to version 78.1.1. An attacker would be allowed to write files to arbitrary locations on the filesystem with the permissions of the process running the Python code, which could escalate to remote code execution depending on the context. Version 78.1.1 fixes the issue.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-47273"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1433</id>
    <title>WID-SEC-W-2025-1433 — Red Hat Enterprise Linux (python-setuptools): Schwachstelle ermöglicht Codeausführung</title>
    <updated>2026-10-02T16:55:14.064326+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in Red Hat Enterprise Linux ausnutzen, um beliebigen Programmcode auszuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1433"/>
  </entry>
</feed>
