Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-59890

Опубликовано: 08 июл. 2026
Источник: redhat
CVSS3: 6.1
EPSS Низкий

Описание

setuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. Prior to 83.0.0, FileList applied MANIFEST.in exclude, global-exclude, recursive-exclude, and prune directives by matching compiled glob patterns against on-disk file names without Unicode normalization, so on macOS APFS or HFS+ an NFD file name could bypass an NFC exclusion rule and be packed into a source distribution. This issue is fixed in version 83.0.0.

A flaw was found in setuptools, a Python package management tool. The FileList component, responsible for handling file exclusions, did not properly normalize Unicode file names when applying exclusion rules. This oversight could allow a specially crafted file name, using a different Unicode normalization form (NFD) on macOS APFS or HFS+ file systems, to bypass an intended exclusion rule (NFC). As a result, sensitive files that should have been excluded could be inadvertently included in a source distribution, leading to information disclosure.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Exploit Intelligenceexploit-intelligence-tech-preview/vulnerability-analysis-rhel9Not affected
Lightspeed Corelightspeed-core/lightspeed-stack-rhel9Not affected
Lightspeed Corelightspeed-core/rag-tool-cpu-rhel9Not affected
Lightspeed Corelightspeed-core/rag-tool-cuda-12.9-rhel9Not affected
Migration Toolkit for Applications 8mta/mta-rhel9-operatorNot affected
Migration Toolkit for Applications 8mta/mta-solution-server-rhel9Not affected
Migration Toolkit for Virtualizationmigration-toolkit-virtualization/mtv-deep-inspection-rhel10Not affected
Migration Toolkit for Virtualizationmigration-toolkit-virtualization/mtv-deep-inspection-rhel9Not affected
Migration Toolkit for Virtualizationmigration-toolkit-virtualization/mtv-rhel9-operatorNot affected
Migration Toolkit for Virtualizationmigration-toolkit-virtualization/mtv-rhv-populator-rhel8Not affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-1025
https://bugzilla.redhat.com/show_bug.cgi?id=2498155setuptools: setuptools: MANIFEST.in exclusion bypass in sdist via Unicode normalization collision (NFC/NFD)

EPSS

Процентиль: 33%
0.00405
Низкий

6.1 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.1
ubuntu
24 дня назад

setuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. Prior to 83.0.0, FileList applied MANIFEST.in exclude, global-exclude, recursive-exclude, and prune directives by matching compiled glob patterns against on-disk file names without Unicode normalization, so on macOS APFS or HFS+ an NFD file name could bypass an NFC exclusion rule and be packed into a source distribution. This issue is fixed in version 83.0.0.

CVSS3: 6.1
nvd
24 дня назад

setuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. Prior to 83.0.0, FileList applied MANIFEST.in exclude, global-exclude, recursive-exclude, and prune directives by matching compiled glob patterns against on-disk file names without Unicode normalization, so on macOS APFS or HFS+ an NFD file name could bypass an NFC exclusion rule and be packed into a source distribution. This issue is fixed in version 83.0.0.

CVSS3: 6.1
msrc
20 дней назад

setuptools: MANIFEST.in exclusion bypass in sdist via Unicode normalization collision (NFC/NFD) on macOS APFS/HFS+

CVSS3: 6.1
debian
24 дня назад

setuptools is a package that allows users to download, build, install, ...

CVSS3: 6.1
github
11 дней назад

setuptools: MANIFEST.in exclusion bypass in sdist via Unicode normalization collision (NFC/NFD) on macOS APFS/HFS+

EPSS

Процентиль: 33%
0.00405
Низкий

6.1 Medium

CVSS3