<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 11:03:12 +0000</lastBuildDate>
    <item>
      <title>ALSA-2026:36193 — Important: python3.14-pip security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2026:36193</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:10: python3.14-pip, AlmaLinux:10: python3.14-pip-wheel&lt;/p&gt;
&lt;p&gt;Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* python-pip: Path traversal via malicious entry point name in pip wheel installation allows arbitrary file overwrite (CVE-2026-8643)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:10: python3.14-pip, AlmaLinux:10: python3.14-pip-wheel&lt;/p&gt;
&lt;p&gt;Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* python-pip: Path traversal via malicious entry point name in pip wheel installation allows arbitrary file overwrite (CVE-2026-8643)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2026:36193</guid>
    </item>
    <item>
      <title>bdu:2026-10841</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-10841</link>
      <description>bdu:2026-10841</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-10841</guid>
    </item>
    <item>
      <title>BELL-CVE-2026-8643</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2026-8643</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: py3-pip, Alpaquita:25: py3-pip, Alpaquita:stream: py3-pip, BellSoft Hardened Containers:23: py3-pip, BellSoft Hardened Containers:25: py3-pip, BellSoft Hardened Containers:stream: py3-pip&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: py3-pip, Alpaquita:25: py3-pip, Alpaquita:stream: py3-pip, BellSoft Hardened Containers:23: py3-pip, BellSoft Hardened Containers:25: py3-pip, BellSoft Hardened Containers:stream: py3-pip&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2026-8643</guid>
    </item>
    <item>
      <title>BREW-azure-cli-CVE-2026-8643 — pip: Path traversal in console_scripts/gui_scripts entry point names allows installing scripts outside of target direct…</title>
      <link>https://cve.radiocsirt.org/vuln/brew-azure-cli-cve-2026-8643</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: azure-cli&lt;/p&gt;
&lt;p&gt;pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: azure-cli&lt;/p&gt;
&lt;p&gt;pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-azure-cli-cve-2026-8643</guid>
    </item>
    <item>
      <title>certfr-2026-avi-0783 — De multiples vulnérabilités ont été découvertes dans Microsoft Azure. Elles permettent à un attaquant de provoquer une…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0783</link>
      <description>certfr-2026-avi-0783</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0783</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-FZ53018 — Security fixes in python3 3.12.13-r1</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-fz53018</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: python3&lt;/p&gt;
&lt;p&gt;Package python3 version 3.12.13-r1 fixes 1 vulnerabilities: CVE-2026-8643&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: python3&lt;/p&gt;
&lt;p&gt;Package python3 version 3.12.13-r1 fixes 1 vulnerabilities: CVE-2026-8643&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-fz53018</guid>
    </item>
    <item>
      <title>EUVD-2026-369279</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-369279</link>
      <description>EUVD-2026-369279</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-369279</guid>
    </item>
    <item>
      <title>fkie_cve-2026-8643</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-8643</link>
      <description>&lt;p&gt;pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-8643</guid>
    </item>
    <item>
      <title>GHSA-wf93-45jw-7689 — pip: Path traversal in console_scripts/gui_scripts entry point names allows installing scripts outside of target direct…</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-wf93-45jw-7689</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: pip&lt;/p&gt;
&lt;p&gt;pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: pip&lt;/p&gt;
&lt;p&gt;pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-wf93-45jw-7689</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-8643 — pip can extract console_scripts and gui_scripts outside installation directory</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-8643</link>
      <description>msrc_CVE-2026-8643</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-8643</guid>
    </item>
    <item>
      <title>OESA-2026-2544 — python-pip security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-2544</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP3: python-pip&lt;/p&gt;
&lt;p&gt;%changelog * Thu May 14 2026 markeryang &amp;amp;amp;lt;747675909@qq.com&amp;amp;amp;gt; - 23.3.1-11 - Fix CVE-2026-3219&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;When following cross-origin redirects for requests made using urllib3&amp;amp;apos;s high-level APIs, such as urllib3.request(), PoolManager.request(), and ProxyManager.request(), sensitive headers — Authorization, Cookie, and Proxy-Authorization (defined in Retry.DEFAULT_REMOVE_HEADERS_ON_REDIRECT) — are stripped by default, as expected. However, cross-origin redirects followed from the low-level API via ProxyManager.connection_from_url().urlopen(..., assert_same_host=False) still forward these sensitive headers.(CVE-2026-44431)&lt;/p&gt;
&lt;p&gt;A flaw was found in pip, the package installer for Python. A remote attacker can exploit this vulnerability by tricking a victim into installing a malicious Python wheel. This wheel contains specially crafted entry-point names that use directory traversal or absolute paths. This allows pip to write generated script wrappers outside the intended installation directory, leading to arbitrary file overwrite. This can severely impact system integrity and availability, and in certain scenarios, may lead to arbitrary code execution.(CVE-2026-8643)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP3: python-pip&lt;/p&gt;
&lt;p&gt;%changelog * Thu May 14 2026 markeryang &amp;amp;amp;lt;747675909@qq.com&amp;amp;amp;gt; - 23.3.1-11 - Fix CVE-2026-3219&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;When following cross-origin redirects for requests made using urllib3&amp;amp;apos;s high-level APIs, such as urllib3.request(), PoolManager.request(), and ProxyManager.request(), sensitive headers — Authorization, Cookie, and Proxy-Authorization (defined in Retry.DEFAULT_REMOVE_HEADERS_ON_REDIRECT) — are stripped by default, as expected. However, cross-origin redirects followed from the low-level API via ProxyManager.connection_from_url().urlopen(..., assert_same_host=False) still forward these sensitive headers.(CVE-2026-44431)&lt;/p&gt;
&lt;p&gt;A flaw was found in pip, the package installer for Python. A remote attacker can exploit this vulnerability by tricking a victim into installing a malicious Python wheel. This wheel contains specially crafted entry-point names that use directory traversal or absolute paths. This allows pip to write generated script wrappers outside the intended installation directory, leading to arbitrary file overwrite. This can severely impact system integrity and availability, and in certain scenarios, may lead to arbitrary code execution.(CVE-2026-8643)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-2544</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:10940-1 — python311-pip-26.1.2-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10940-1</link>
      <description>&lt;p&gt;python311-pip-26.1.2-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;python311-pip-26.1.2-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:10940-1</guid>
    </item>
    <item>
      <title>PYSEC-2026-196</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2026-196</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: pip&lt;/p&gt;
&lt;p&gt;pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: pip&lt;/p&gt;
&lt;p&gt;pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2026-196</guid>
    </item>
    <item>
      <title>RHSA-2026:33313 — Red Hat Security Advisory: A Subscription Management tool for finding and reporting Red Hat product usage</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:33313</link>
      <description>&lt;p&gt;libxml2: buffer over-read in xmlHTMLPrintFileContext in xmllint.c coreutils: Heap Buffer Under-Read in GNU Coreutils sort via Key Specification libxslt: use-after-free with key data stored cross-RVT libtasn1: libtasn1: Denial of Service via stack-based buffer overflow in asn1_expend_octet_string image-size: image-size: Denial of Service due to infinite loop when processing specially crafted images. python-pip: Path traversal via malicious entry point name in pip wheel installation allows arbitrary file overwrite nginx: ngx_http_rewrite_module: code execution and denial of service openssl: openssl: Information Disclosure from Uninitialized Memory via Invalid RSA Public Key libpng: libpng: Arbitrary code execution due to use-after-free vulnerability libpng: libpng: Information disclosure and denial of service via out-of-bounds read/write in Neon palette expansion vim: Command injection allows arbitrary code execution via malicious tag files urllib3: urllib3: Information disclosure via cross-origin redirects forwarding sensitive headers urllib3: urllib3: Denial of Service due to excessive HTTP response decompression&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;libxml2: buffer over-read in xmlHTMLPrintFileContext in xmllint.c coreutils: Heap Buffer Under-Read in GNU Coreutils sort via Key Specification libxslt: use-after-free with key data stored cross-RVT libtasn1: libtasn1: Denial of Service via stack-based buffer overflow in asn1_expend_octet_string image-size: image-size: Denial of Service due to infinite loop when processing specially crafted images. python-pip: Path traversal via malicious entry point name in pip wheel installation allows arbitrary file overwrite nginx: ngx_http_rewrite_module: code execution and denial of service openssl: openssl: Information Disclosure from Uninitialized Memory via Invalid RSA Public Key libpng: libpng: Arbitrary code execution due to use-after-free vulnerability libpng: libpng: Information disclosure and denial of service via out-of-bounds read/write in Neon palette expansion vim: Command injection allows arbitrary code execution via malicious tag files urllib3: urllib3: Information disclosure via cross-origin redirects forwarding sensitive headers urllib3: urllib3: Denial of Service due to excessive HTTP response decompression&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:33313</guid>
    </item>
    <item>
      <title>RLSA-2026:36193 — Important: python3.14-pip security update</title>
      <link>https://cve.radiocsirt.org/vuln/rlsa-2026:36193</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:10: python3.14-pip&lt;/p&gt;
&lt;p&gt;Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* python-pip: Path traversal via malicious entry point name in pip wheel installation allows arbitrary file overwrite (CVE-2026-8643)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:10: python3.14-pip&lt;/p&gt;
&lt;p&gt;Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* python-pip: Path traversal via malicious entry point name in pip wheel installation allows arbitrary file overwrite (CVE-2026-8643)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rlsa-2026:36193</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:22300-1 — Security update for python-pip</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:22300-1</link>
      <description>&lt;p&gt;Security update for python-pip&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for python-pip&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:22300-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-8643</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-8643</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: python-pip, Ubuntu:Pro:16.04:LTS: python-pip, Ubuntu:Pro:18.04:LTS: python-pip, Ubuntu:Pro:20.04:LTS: python-pip, Ubuntu:Pro:22.04:LTS: python-pip, Ubuntu:Pro:24.04:LTS: python-pip, Ubuntu:25.10: python-pip, Ubuntu:Pro:26.04:LTS: python-pip&lt;/p&gt;
&lt;p&gt;pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: python-pip, Ubuntu:Pro:16.04:LTS: python-pip, Ubuntu:Pro:18.04:LTS: python-pip, Ubuntu:Pro:20.04:LTS: python-pip, Ubuntu:Pro:22.04:LTS: python-pip, Ubuntu:Pro:24.04:LTS: python-pip, Ubuntu:25.10: python-pip, Ubuntu:Pro:26.04:LTS: python-pip&lt;/p&gt;
&lt;p&gt;pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-8643</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2222 — Red Hat Enterprise Linux (python-pip): Schwachstelle ermöglicht Codeausführung</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2222</link>
      <description>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in Red Hat Enterprise Linux ausnutzen, um beliebige Dateien zu überschreiben und möglicherweise beliebigen Code auszuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in Red Hat Enterprise Linux ausnutzen, um beliebige Dateien zu überschreiben und möglicherweise beliebigen Code auszuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2222</guid>
    </item>
  </channel>
</rss>
