Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 13

Количество 13

fstec логотип

BDU:2026-09330

4 месяца назад

Уязвимость функции zipfile.is_zipfile() модуля pip языка программирования Python, позволяющая нарушителю записывать произвольные файлы

CVSS3: 3.3
EPSS: Низкий
redos логотип

ROS-20260624-73-0017

около 1 месяца назад

Уязвимость python-pip

CVSS3: 3.3
EPSS: Низкий
ubuntu логотип

CVE-2026-3219

3 месяца назад

pip handles concatenated tar and ZIP files as ZIP files regardless of filename or whether a file is both a tar and ZIP file. This behavior could result in confusing installation behavior, such as installing "incorrect" files according to the filename of the archive. New behavior only proceeds with installation if the file identifies uniquely as a ZIP or tar archive, not as both.

EPSS: Низкий
redhat логотип

CVE-2026-3219

3 месяца назад

pip handles concatenated tar and ZIP files as ZIP files regardless of filename or whether a file is both a tar and ZIP file. This behavior could result in confusing installation behavior, such as installing "incorrect" files according to the filename of the archive. New behavior only proceeds with installation if the file identifies uniquely as a ZIP or tar archive, not as both.

CVSS3: 5
EPSS: Низкий
nvd логотип

CVE-2026-3219

3 месяца назад

pip handles concatenated tar and ZIP files as ZIP files regardless of filename or whether a file is both a tar and ZIP file. This behavior could result in confusing installation behavior, such as installing "incorrect" files according to the filename of the archive. New behavior only proceeds with installation if the file identifies uniquely as a ZIP or tar archive, not as both.

EPSS: Низкий
msrc логотип

CVE-2026-3219

3 месяца назад

pip doesn't reject concatenated ZIP and tar archives

EPSS: Низкий
debian логотип

CVE-2026-3219

3 месяца назад

pip handles concatenated tar and ZIP files as ZIP files regardless of ...

EPSS: Низкий
github логотип

GHSA-58qw-9mgm-455v

3 месяца назад

pip has an interpretation conflict due to handling both concatenated tar and ZIP files as ZIP files

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2758-1

около 1 месяца назад

Security update for python-pip

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20880-1

2 месяца назад

Security update for python-pip

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2634-1

около 1 месяца назад

Security update for python-pip

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2387-1

около 2 месяцев назад

Security update for python

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2664-1

около 1 месяца назад

Security update for python, python-base, python-doc

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
fstec логотип
BDU:2026-09330

Уязвимость функции zipfile.is_zipfile() модуля pip языка программирования Python, позволяющая нарушителю записывать произвольные файлы

CVSS3: 3.3
0%
Низкий
4 месяца назад
redos логотип
ROS-20260624-73-0017

Уязвимость python-pip

CVSS3: 3.3
0%
Низкий
около 1 месяца назад
ubuntu логотип
CVE-2026-3219

pip handles concatenated tar and ZIP files as ZIP files regardless of filename or whether a file is both a tar and ZIP file. This behavior could result in confusing installation behavior, such as installing "incorrect" files according to the filename of the archive. New behavior only proceeds with installation if the file identifies uniquely as a ZIP or tar archive, not as both.

0%
Низкий
3 месяца назад
redhat логотип
CVE-2026-3219

pip handles concatenated tar and ZIP files as ZIP files regardless of filename or whether a file is both a tar and ZIP file. This behavior could result in confusing installation behavior, such as installing "incorrect" files according to the filename of the archive. New behavior only proceeds with installation if the file identifies uniquely as a ZIP or tar archive, not as both.

CVSS3: 5
0%
Низкий
3 месяца назад
nvd логотип
CVE-2026-3219

pip handles concatenated tar and ZIP files as ZIP files regardless of filename or whether a file is both a tar and ZIP file. This behavior could result in confusing installation behavior, such as installing "incorrect" files according to the filename of the archive. New behavior only proceeds with installation if the file identifies uniquely as a ZIP or tar archive, not as both.

0%
Низкий
3 месяца назад
msrc логотип
CVE-2026-3219

pip doesn't reject concatenated ZIP and tar archives

0%
Низкий
3 месяца назад
debian логотип
CVE-2026-3219

pip handles concatenated tar and ZIP files as ZIP files regardless of ...

0%
Низкий
3 месяца назад
github логотип
GHSA-58qw-9mgm-455v

pip has an interpretation conflict due to handling both concatenated tar and ZIP files as ZIP files

0%
Низкий
3 месяца назад
suse-cvrf логотип
SUSE-SU-2026:2758-1

Security update for python-pip

около 1 месяца назад
suse-cvrf логотип
openSUSE-SU-2026:20880-1

Security update for python-pip

2 месяца назад
suse-cvrf логотип
SUSE-SU-2026:2634-1

Security update for python-pip

около 1 месяца назад
suse-cvrf логотип
SUSE-SU-2026:2387-1

Security update for python

около 2 месяцев назад
suse-cvrf логотип
SUSE-SU-2026:2664-1

Security update for python, python-base, python-doc

около 1 месяца назад

Уязвимостей на страницу