Security fix for CVE-2026-3219 in the bundled pip wheel . -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-130f7539d3 2026-05-17 01:26:47.130170+00:00 -------------------------------------------------------------------------------- Name : pypy Product : Fedora 44 Version : 7.3.22 Release : 2.fc44 URL : https://www.pypy.org/ Summary : Python implementation with a Just-In-Time compiler Description : PyPy's implementation of Python, featuring a Just-In-Time compiler on some CPU architectures, and various optimized implementations of the standard types (strings, dictionaries, etc) This build of PyPy has JIT-compilation enabled. -------------------------------------------------------------------------------- Update Information: Security fix for CVE-2026-3219 in the bundled pip wheel -------------------------------------------------------------------------------- ChangeLog: * Tue May 5 2026 Charalampos Stratakis - 7.3.22-2 - Security fix for CVE-2026-3219 in the bundled pip wheel - Fixes: rhbz#2461288 * Tue May 5 2026 Charalampos Stratakis - 7.3.22-1 - Update to 7.3.22 - Fixes: rhbz#2463475 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2461288 - CVE-2026-3219 pypy: pip: Incorrect file installation due to improper archive handling [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2461288 [ 2 ] Bug #2463475 - pypy-7.3.22 is available https://bugzilla.redhat.com/show_bug.cgi?id=2463475 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-130f7539d3' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed withthe Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Security fix for CVE-2026-3219 in the bundled pip wheel. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-3505a95524 2026-05-17 00:48:46.610623+00:00 -------------------------------------------------------------------------------- Name : pypy Product : Fedora 43 Version : 7.3.22 Release : 2.fc43 URL : https://www.pypy.org/ Summary : Python implementation with a Just-In-Time compiler Description : PyPy's implementation of Python, featuring a Just-In-Time compiler on some CPU architectures, and various optimized implementations of the standard types (strings, dictionaries, etc) This build of PyPy has JIT-compilation enabled. -------------------------------------------------------------------------------- Update Information: Security fix for CVE-2026-3219 in the bundled pip wheel -------------------------------------------------------------------------------- ChangeLog: * Tue May 5 2026 Charalampos Stratakis - 7.3.22-2 - Security fix for CVE-2026-3219 in the bundled pip wheel - Fixes: rhbz#2461288 * Tue May 5 2026 Charalampos Stratakis - 7.3.22-1 - Update to 7.3.22 - Fixes: rhbz#2463475 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2461288 - CVE-2026-3219 pypy: pip: Incorrect file installation due to improper archive handling [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2461288 [ 2 ] Bug #2463475 - pypy-7.3.22 is available https://bugzilla.redhat.com/show_bug.cgi?id=2463475 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-3505a95524' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with theFedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Several security issues were fixed in pip.. ========================================================================== Ubuntu Security Notice USN-7762-1 September 23, 2025 python-pip vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 25.04 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS Summary: Several security issues were fixed in pip. Software Description: - python-pip: Python package installer Details: Dennis Brinkrolf and Tobias Funke discovered that Requests incorrectly leaked Proxy-Authorization headers. A remote attacker could possibly use this issue to obtain sensitive information. This update addresses the issue in the Requests module bundled into pip in Ubuntu 22.04 LTS. (CVE-2023-32681) It was discovered that urllib3 didn't strip HTTP body on status code 303 redirects under certain circumstances. A remote attacker could possibly use this issue to obtain sensitive information. This update addresses the issue in the urllib3 module bundled into pip in Ubuntu 24.04 LTS. (CVE-2023-45803) Guido Vranken discovered that idna did not properly manage certain inputs, which could lead to significant resource consumption. An attacker could possibly use this issue to cause a denial of service. This update addresses the issue in the idna module bundled into pip in Ubuntu 22.04 LTS and Ubuntu 24.04 LTS. (CVE-2024-3651) Juho Forsén discovered that Requests did not correctly parse URLs. A remote attacker could possibly use this issue to leak sensitive information. This update addresses the issue in the Requests module bundled into pip in Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 25.04. (CVE-2024-47081) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 25.04 python3-pip 25.0+dfsg-1ubuntu0.2 python3-pip-whl 25.0+dfsg-1ubuntu0.2 Ubuntu 24.04 LTS python3-pip 24.0+dfsg-1ubuntu1.3 python3-pip-whl 24.0+dfsg-1ubuntu1.3 Ubuntu 22.04 LTS python3-pip 22.0.2+dfsg-1ubuntu0.7 python3-pip-whl 22.0.2+dfsg-1ubuntu0.7 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7762-1 CVE-2023-32681, CVE-2023-45803, CVE-2024-3651, CVE-2024-47081, https://bugs.launchpad.net/ubuntu/+source/python-pip/+bug/2031880 Package Information: https://launchpad.net/ubuntu/+source/python-pip/25.0+dfsg-1ubuntu0.2 https://launchpad.net/ubuntu/+source/python-pip/24.0+dfsg-1ubuntu1.3 https://launchpad.net/ubuntu/+source/python-pip/22.0.2+dfsg-1ubuntu0.7 . Tackle urgent vulnerabilities in pip impacting Ubuntu distributions. Safeguard against information breaches and operational outages immediately!. pip security Ubuntu issues remote access risks. . Severity: Critical. LinuxSecurity.com Team
A vulnerability has been discovered in pip, which could lead to arbitrary configuration options being injected.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202501-03 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: pip: arbitrary configuration injection Date: January 17, 2025 Bugs: #918427 ID: 202501-03 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======== A vulnerability has been discovered in pip, which could lead to arbitrary configuration options being injected. Background ========== pip is a tool for installing and managing Python packages. Affected packages ================= Package Vulnerable Unaffected -------------- ------------ ------------ dev-python/pip < 23.3 > = 23.3 Description =========== Multiple vulnerabilities have been discovered in pip. Please review the CVE identifiers referenced below for details. Impact ====== When installing a package from a Mercurial VCS URL (ie "pip install hg+..."), the specified Mercurial revision could be used to inject arbitrary configuration options to the "hg clone" call (ie "--config"). Controlling the Mercurial configuration can modify how and which repository is installed. This vulnerability does not affect users who aren't installing from Mercurial. Workaround ========== There is no known workaround at this time. Resolution ========== All pip users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =dev-python/pip-23.3" References ========== [ 1 ] CVE-2023-5752 https://nvd.nist.gov/vuln/detail/CVE-2023-5752 Availability ============ This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202501-03 Concerns? ========= Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to
Security fix for CVE-2023-5752 (in the bundled pip).. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-797928fed3 2024-05-10 01:33:48.476520 -------------------------------------------------------------------------------- Name : pypy Product : Fedora 38 Version : 7.3.15 Release : 3.fc38 URL : https://pypy.org/ Summary : Python implementation with a Just-In-Time compiler Description : PyPy's implementation of Python, featuring a Just-In-Time compiler on some CPU architectures, and various optimized implementations of the standard types (strings, dictionaries, etc) This build of PyPy has JIT-compilation enabled. -------------------------------------------------------------------------------- Update Information: Security fix for CVE-2023-5752 (in the bundled pip). -------------------------------------------------------------------------------- ChangeLog: * Tue Apr 30 2024 Charalampos Stratakis - 7.3.15-3 - Security fix for CVE-2023-5752 for the bundled pip wheel - Resolves: rhbz#2250771 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2250765 - CVE-2023-5752 pip: Mercurial configuration injectable in repo revision when installing via pip https://bugzilla.redhat.com/show_bug.cgi?id=2250765 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-797928fed3' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Security fix for CVE-2023-5752 (in the bundled pip).. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-612986fdfa 2024-05-09 01:38:47.479807 -------------------------------------------------------------------------------- Name : pypy Product : Fedora 40 Version : 7.3.15 Release : 3.fc40 URL : https://pypy.org/ Summary : Python implementation with a Just-In-Time compiler Description : PyPy's implementation of Python, featuring a Just-In-Time compiler on some CPU architectures, and various optimized implementations of the standard types (strings, dictionaries, etc) This build of PyPy has JIT-compilation enabled. -------------------------------------------------------------------------------- Update Information: Security fix for CVE-2023-5752 (in the bundled pip). -------------------------------------------------------------------------------- ChangeLog: * Tue Apr 30 2024 Charalampos Stratakis - 7.3.15-3 - Security fix for CVE-2023-5752 for the bundled pip wheel - Resolves: rhbz#2250771 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2250765 - CVE-2023-5752 pip: Mercurial configuration injectable in repo revision when installing via pip https://bugzilla.redhat.com/show_bug.cgi?id=2250765 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-612986fdfa' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Multiple vulnerabilities have been found in pip, which may allow remote attackers to execute arbitrary code or local attackers to conduct symlink attacks. [More...]. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 201309-05 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: pip: Multiple vulnerabilities Date: September 12, 2013 Bugs: #462616, #480202 ID: 201309-05 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Multiple vulnerabilities have been found in pip, which may allow remote attackers to execute arbitrary code or local attackers to conduct symlink attacks. Background ========= pip is a tool for installing and managing Python packages. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 dev-python/pip < 1.3.1 > = 1.3.1 Description ========== Multiple vulnerabilities have been discovered in pip. Please review the CVE identifiers referenced below for details. Impact ===== A remote attacker could conduct a Man-in-the-Middle attack to cause pip to execute arbitrary code. A local attacker could perform symlink attacks to overwrite arbitrary files with the privileges of the user running the application. Workaround ========= There is no known workaround at this time. Resolution ========= All pip users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =dev-python/pip-1.3.1" References ========= [ 1 ] CVE-2013-1629 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-1629 [ 2 ] CVE-2013-1888 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-1888 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/201309-05 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to
Get the latest Linux and open source security news straight to your inbox.