Pypa
Pypa PIP: vulnerabilidades y CVE
Pypa PIP tiene 15 vulnerabilidades publicadas, 5 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE15
Últimos 12 meses5
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-13346 | Media (5.6) | 0.29% | — | 29 jul 2026 | pip would incorrectly handle doubly-encoded package URLs from indexes allowing for files to be installed to arbitrary locations on disk even when installing wheels. This vulnerability requires downloading or installing… |
| CVE-2026-8643 | Media (4.1) | 0.47% | — | 1 jun 2026 | pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the… |
| CVE-2026-6357 | Media (5.3) | 0.17% | — | 27 abr 2026 | pip prior to version 26.1 would run self-update check functionality after installing wheel files which required importing well-known Python modules names. These module imports were intentionally deferred to increase… |
| CVE-2026-3219 | Media (4.6) | 0.18% | — | 20 abr 2026 | pip handles concatenated tar and ZIP files as ZIP files regardless of filename or whether a file is both a tar and ZIP file. This behavior could result in confusing installation behavior, such as installing "incorrect"… |
| CVE-2026-1703 | Baja (2) | 0.44% | — | 2 feb 2026 | When pip is installing and extracting a maliciously crafted wheel archive, files may be extracted outside the installation directory. The path traversal is limited to prefixes of the installation directory, thus isn't… |
| CVE-2025-8869 | Media (5.9) | 0.47% | — | 24 sept 2025 | When extracting a tar archive pip may not check symbolic links point into the extraction directory if the tarfile module doesn't implement PEP 706. Note that upgrading pip to a "fixed" version for this vulnerability… |
| CVE-2024-21574 | Crítica (10) | 1.1% | — | 12 dic 2024 | The issue stems from a missing validation of the pip field in a POST request sent to the /customnode/install endpoint used to install custom nodes which is added to the server by the extension. This allows an attacker… |
| CVE-2023-5752 | Baja (3.3) | 0.48% | — | 25 oct 2023 | When installing a package from a Mercurial VCS URL (ie "pip install hg+...") with pip prior to v23.3, the specified Mercurial revision could be used to inject arbitrary configuration options to the "hg clone" call (ie… |
| CVE-2021-3572 | Media (5.7) | 1.8% | — | 10 nov 2021 | A flaw was found in python-pip in the way it handled Unicode separators in git references. A remote attacker could possibly use this issue to install a different revision on a repository. The highest threat from this… |
| CVE-2019-20916 | Alta (7.5) | 3.0% | — | 4 sept 2020 | The pip package before 19.2 for Python allows Directory Traversal when a URL is given in an install command, because a Content-Disposition header can have ../ in a filename, as demonstrated by overwriting the… |
| CVE-2018-20225 | Alta (7.8) | 1.8% | — | 8 may 2020 | An issue was discovered in pip (all versions) because it installs the version with the highest version number, even if the user had intended to obtain a private package from a private index. This only affects use of the… |
| CVE-2013-5123 | Media (5.9) | 8.0% | — | 5 nov 2019 | The mirroring support (-M, --use-mirrors) in Python Pip before 1.5 uses insecure DNS querying and authenticity checks which allows attackers to perform man-in-the-middle attacks. |
| CVE-2014-8991 | Baja (2.1) | 0.39% | — | 24 nov 2014 | pip 1.3 through 1.5.6 allows local users to cause a denial of service (prevention of package installation) by creating a /tmp/pip-build-* file for another user. |
| CVE-2013-1888 | Baja (2.1) | 0.36% | — | 17 ago 2013 | pip before 1.3 allows local users to overwrite arbitrary files via a symlink attack on a file in the /tmp/pip-build temporary directory. |
| CVE-2013-1629 | Media (6.8) | 6.2% | — | 6 ago 2013 | pip before 1.3 uses HTTP to retrieve packages from the PyPI repository, and does not perform integrity checks on package contents, which allows man-in-the-middle attackers to execute arbitrary code via a crafted… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.