Skip to main content
EPSS 0.4%top 66%

setuptools: MANIFEST.in exclusion bypass in sdist via Unicode normalization collision (NFC/NFD) on macOS APFS/HFS+ (CVE-2026-59890)

0
Medium
Published: 07/14/2026 (07/14/2026, 08:55:22 UTC)
Source: GCVE Database
Product: setuptools

Description

setuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. Prior to 83.0.0, FileList applied MANIFEST.in exclude, global-exclude, recursive-exclude, and prune directives by matching compiled glob patterns against on-disk file names without Unicode normalization, so on macOS APFS or HFS+ an NFD file name could bypass an NFC exclusion rule and be packed into a source distribution. This issue is fixed in version 83.0.0.

Affected software

Affected versions
=26.1.1.2-r0Red HatRed Hat Hardened Imagessrcpython-setuptools-main@src<83.0.0

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/15/2026, 00:25:53 UTC

Technical Analysis

The vulnerability CVE-2026-59890 exists in setuptools, a Python package management tool. The FileList component responsible for file exclusions does not properly normalize Unicode file names when applying exclusion rules. On macOS APFS or HFS+ file systems, a specially crafted file name using a different Unicode normalization form (NFD) can bypass an intended exclusion rule (NFC). This results in sensitive files that should have been excluded being included in source distributions, leading to potential information disclosure. Red Hat has issued a fix in the miniforge3 package version 26.3.2.3-r0 and related RPMs, including python-setuptools 83.0.0-4.hum1. The CVSS v3.1 base score assigned by Red Hat is 6.1 (medium severity), with a local attack vector, low complexity, no privileges required, user interaction required, and high confidentiality impact.

Potential Impact

The vulnerability can cause sensitive files that should be excluded from source distributions to be included due to Unicode normalization bypass. This leads to potential information disclosure. The integrity and availability impacts are low or none. The attack requires local access and user interaction, with low complexity and no privileges required.

Mitigation Recommendations

A security update is available and should be applied. Red Hat has released fixed versions of the affected packages, including python-setuptools 83.0.0-4.hum1 and related RPMs in miniforge3 version 26.3.2.3-r0. Users should upgrade to these fixed versions to remediate the vulnerability. No other mitigations meeting Red Hat's criteria are currently available.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2026:37530
Cve Count
1
Cvss Version
3.1
State
PUBLISHED

Threat ID: 6a5c47772a4a8d5989eb4fe8

Added to database: 07/19/2026, 03:41:43 UTC

Last enriched: 08/15/2026, 00:25:53 UTC

Last updated: 09/14/2026, 10:01:32 UTC

Views: 69

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses