Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-59890

Опубликовано: 08 июл. 2026
Источник: nvd
CVSS3: 6.1
EPSS Низкий

Описание

setuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. Prior to 83.0.0, FileList applied MANIFEST.in exclude, global-exclude, recursive-exclude, and prune directives by matching compiled glob patterns against on-disk file names without Unicode normalization, so on macOS APFS or HFS+ an NFD file name could bypass an NFC exclusion rule and be packed into a source distribution. This issue is fixed in version 83.0.0.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:python:setuptools:*:*:*:*:*:*:*:*
Версия до 83.0.0 (исключая)

EPSS

Процентиль: 33%
0.00405
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-176

Связанные уязвимости

CVSS3: 6.1
ubuntu
24 дня назад

setuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. Prior to 83.0.0, FileList applied MANIFEST.in exclude, global-exclude, recursive-exclude, and prune directives by matching compiled glob patterns against on-disk file names without Unicode normalization, so on macOS APFS or HFS+ an NFD file name could bypass an NFC exclusion rule and be packed into a source distribution. This issue is fixed in version 83.0.0.

CVSS3: 6.1
redhat
24 дня назад

setuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. Prior to 83.0.0, FileList applied MANIFEST.in exclude, global-exclude, recursive-exclude, and prune directives by matching compiled glob patterns against on-disk file names without Unicode normalization, so on macOS APFS or HFS+ an NFD file name could bypass an NFC exclusion rule and be packed into a source distribution. This issue is fixed in version 83.0.0.

CVSS3: 6.1
msrc
20 дней назад

setuptools: MANIFEST.in exclusion bypass in sdist via Unicode normalization collision (NFC/NFD) on macOS APFS/HFS+

CVSS3: 6.1
debian
24 дня назад

setuptools is a package that allows users to download, build, install, ...

EPSS

Процентиль: 33%
0.00405
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-176