Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

fstec логотип

BDU:2026-10841

Опубликовано: 01 июн. 2026
Источник: fstec
CVSS3: 5.5
CVSS2: 4.6
EPSS Низкий

Описание

Уязвимость модуля pip языка программирования Python связана с неверным ограничением имени пути к каталогу. Эксплуатация уязвимости может позволить нарушителю оказать воздействие на целостность защищаемой информации

Вендор

Red Hat, Inc.
ООО «Ред Софт»
Python Software Foundation

Наименование ПО

Red Hat Enterprise Linux
РЕД ОС
Red Hat OpenShift Container Platform
Migration Toolkit for Virtualization
OpenShift Dev Spaces
OpenShift AI
Red Hat Trusted Artifact Signer
Red Hat AI Inference Server
Ansible Automation Platform
Red Hat Enterprise Linux AI
Discovery
Pen Drive Powered by Red Hat Lightspeed
Red Hat Hardened Images
Migration Toolkit for Applications
Exploit Intelligence
Python-pip

Версия ПО

8 (Red Hat Enterprise Linux)
7.3 (РЕД ОС)
4 (Red Hat OpenShift Container Platform)
9 (Red Hat Enterprise Linux)
- (Migration Toolkit for Virtualization)
- (OpenShift Dev Spaces)
- (OpenShift AI)
- (Red Hat Trusted Artifact Signer)
10 (Red Hat Enterprise Linux)
- (Red Hat AI Inference Server)
2.5 for RHEL 8 (Ansible Automation Platform)
8.0 (РЕД ОС)
2.25 (OpenShift AI)
3 (Red Hat Enterprise Linux AI)
2 (Discovery)
3.3 (OpenShift AI)
2 (Ansible Automation Platform)
- (Pen Drive Powered by Red Hat Lightspeed)
- (Red Hat Hardened Images)
8 (Migration Toolkit for Applications)
2.6 (Ansible Automation Platform)
1.4 (Red Hat Trusted Artifact Signer)
- (Exploit Intelligence)
2.5 (Ansible Automation Platform)
до 26.1.2 (Python-pip)
3.0 (OpenShift AI)
3.2 (OpenShift AI)
3.4 (OpenShift AI)

Тип ПО

Операционная система
Прикладное ПО информационных систем
ПО виртуализации/ПО виртуального программно-аппаратного средства
ПО для разработки ИИ

Операционные системы и аппаратные платформы

Red Hat, Inc. Red Hat Enterprise Linux 8
ООО «Ред Софт» РЕД ОС 7.3
Red Hat, Inc. Red Hat Enterprise Linux 9
Red Hat, Inc. Red Hat Enterprise Linux 10
ООО «Ред Софт» РЕД ОС 8.0
Red Hat, Inc. Red Hat Enterprise Linux AI 3

Уровень опасности уязвимости

Средний уровень опасности (базовая оценка CVSS 2.0 составляет 4,6)
Средний уровень опасности (базовая оценка CVSS 3.1 составляет 5,5)

Возможные меры по устранению уязвимости

Использование рекомендаций:
Для pip:
https://github.com/pypa/pip/pull/14000
Для Ред ОС:
https://redos.red-soft.ru/search/?iblock_id=24&q=CVE-2026-8643
Для программных продуктов Red Hat Inc.:
https://access.redhat.com/security/cve/cve-2026-8643

Статус уязвимости

Подтверждена производителем

Наличие эксплойта

Данные уточняются

Информация об устранении

Уязвимость устранена

Идентификаторы других систем описаний уязвимостей

EPSS

Процентиль: 25%
0.0032
Низкий

5.5 Medium

CVSS3

4.6 Medium

CVSS2

Связанные уязвимости

CVSS3: 5
redos
2 месяца назад

Уязвимость python-pip

CVSS3: 5.5
ubuntu
4 месяца назад

pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory.

CVSS3: 8
redhat
4 месяца назад

pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory.

CVSS3: 5.5
nvd
4 месяца назад

pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory.

msrc
3 месяца назад

pip can extract console_scripts and gui_scripts outside installation directory

EPSS

Процентиль: 25%
0.0032
Низкий

5.5 Medium

CVSS3

4.6 Medium

CVSS2