Skip to main content
EPSS 0.3%top 78%

Security update for python-pip

0
Medium
Published: 08/25/2026 (08/25/2026, 06:31:46 UTC)
Source: GCVE Database
Vendor/Project: SUSE Product Security Team
Product: SUSE

Description

A vulnerability in python-pip (CVE-2026-13346) allows incorrect handling of doubly-encoded package URLs from malicious package indexes, enabling files to be installed to arbitrary locations on disk. This primarily affects users running the pip download command with the --only-binary option. The issue could lead to system compromise by allowing an attacker to overwrite or create critical files. A patch is available from vendors including Red Hat.

Affected software

Affected versions
=26.1.1.3-r1=3.0=3.11.15-r1

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/17/2026, 03:17:19 UTC

Technical Analysis

CVE-2026-13346 is a vulnerability in python-pip where the software incorrectly processes doubly-encoded package URLs from malicious package indexes. This flaw allows a remote attacker to convince a user to download or install a package that results in files being installed to arbitrary locations on the system. The vulnerability mainly impacts users who use the pip download command with the --only-binary option. The flaw involves improper limitation of a pathname to a restricted directory (CWE-22, CWE-36). Red Hat has issued a security update fixing this issue in python-pip packages. The vulnerability has a medium severity rating and no known exploits in the wild have been reported.

Potential Impact

An attacker can exploit this vulnerability by hosting a malicious package index with doubly-encoded URLs, causing pip to install files to arbitrary locations on disk. This can lead to overwriting or creating critical files, potentially resulting in system compromise, unauthorized code execution, or bypassing security mechanisms. The vulnerability affects the integrity and confidentiality of the system and may also impact availability if critical files are corrupted or deleted. It primarily affects users running pip download with the --only-binary option; installing source distributions from untrusted indexes is already unsafe.

Mitigation Recommendations

A patch is available and should be applied to affected python-pip packages. Red Hat and other vendors have released updates that fix this vulnerability. Users should update to the fixed versions as soon as possible. No additional mitigations are specifically recommended beyond applying the official fix. Users not using the --only-binary option are less impacted, but updating remains advised.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2026:48788
Cve Count
1
State
PUBLISHED

Threat ID: 6a6fb62dbf32cb7a346e738c

Added to database: 08/02/2026, 21:27:09 UTC

Last enriched: 09/17/2026, 03:17:19 UTC

Last updated: 09/17/2026, 03:27:43 UTC

Views: 61

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses