UBUNTU-CVE-2026-59890
A vulnerability in setuptools prior to version 83.0.0 allows certain file exclusion rules in MANIFEST.in to be bypassed on macOS file systems using Unicode normalization forms. This can cause unintended files to be included in source distributions. The issue is fixed in setuptools version 83.0.0.
AI Analysis
Technical Summary
The setuptools package applied MANIFEST.in exclude, global-exclude, recursive-exclude, and prune directives by matching compiled glob patterns against on-disk file names without Unicode normalization. On macOS APFS or HFS+ file systems, file names stored in Normalization Form D (NFD) could bypass exclusion rules written in Normalization Form C (NFC), resulting in those files being included in source distributions when they should have been excluded. This vulnerability affects setuptools versions prior to 83.0.0 and is resolved by normalizing file names before pattern matching in version 83.0.0.
Potential Impact
This vulnerability can lead to unintended files being included in source distributions on macOS systems using APFS or HFS+ file systems. This may expose sensitive or unwanted files in distributed packages, potentially leading to information disclosure. There is no indication of integrity or availability impact. The CVSS vector indicates local attack vector with low attack complexity, no privileges required, user interaction required, and high confidentiality impact but low integrity and availability impact.
Mitigation Recommendations
Upgrade setuptools to version 83.0.0 or later, where the issue is fixed by applying Unicode normalization before matching file names against exclusion patterns. No other mitigation is indicated.
UBUNTU-CVE-2026-59890
Description
A vulnerability in setuptools prior to version 83.0.0 allows certain file exclusion rules in MANIFEST.in to be bypassed on macOS file systems using Unicode normalization forms. This can cause unintended files to be included in source distributions. The issue is fixed in setuptools version 83.0.0.
CVSS v3.1
Score 6.1medium
Affected software
pkg:deb/ubuntu/[email protected]?arch=source&distro=focalpkg:deb/ubuntu/[email protected]?arch=source&distro=jammypkg:deb/ubuntu/[email protected]?arch=source&distro=noblepkg:deb/ubuntu/[email protected]?arch=source&distro=questingpkg:deb/ubuntu/[email protected]?arch=source&distro=resoluteRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The setuptools package applied MANIFEST.in exclude, global-exclude, recursive-exclude, and prune directives by matching compiled glob patterns against on-disk file names without Unicode normalization. On macOS APFS or HFS+ file systems, file names stored in Normalization Form D (NFD) could bypass exclusion rules written in Normalization Form C (NFC), resulting in those files being included in source distributions when they should have been excluded. This vulnerability affects setuptools versions prior to 83.0.0 and is resolved by normalizing file names before pattern matching in version 83.0.0.
Potential Impact
This vulnerability can lead to unintended files being included in source distributions on macOS systems using APFS or HFS+ file systems. This may expose sensitive or unwanted files in distributed packages, potentially leading to information disclosure. There is no indication of integrity or availability impact. The CVSS vector indicates local attack vector with low attack complexity, no privileges required, user interaction required, and high confidentiality impact but low integrity and availability impact.
Mitigation Recommendations
Upgrade setuptools to version 83.0.0 or later, where the issue is fixed by applying Unicode normalization before matching file names against exclusion patterns. No other mitigation is indicated.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- UBUNTU-CVE-2026-59890
- Osv Schema Version
- 1.7.0
- Aliases
- []
- Ecosystems
- ["Ubuntu:20.04:LTS","Ubuntu:22.04:LTS","Ubuntu:24.04:LTS","Ubuntu:25.10","Ubuntu:26.04:LTS"]
- Database Specific Severity
- null
- Cvss Version
- 3.1
Threat ID: 6a58b45468715ace43d6b997
Added to database: 07/16/2026, 10:37:08 UTC
Last enriched: 07/16/2026, 11:31:17 UTC
Last updated: 07/31/2026, 19:24:46 UTC
Views: 18
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.