Pypi · Virtualenv · CVE-2026-102930
**Name of the Vulnerable Software and Affected Versions**
virtualenv versions prior to 21.7.12
**Description**
The `download wheel()` function fails to verify the bytes of pip and setuptools seed wheels fetched during periodic updates or via the `--download` option against an authoritative digest, unlike the BUNDLE SHA256 verification used for embedded wheels. This allows a compromised index, stale mirror, or intercepted TLS connection to substitute a malicious wheel under the requested distribution, version, and filename. Once substituted, the attacker-controlled wheel is cached and seeded into all subsequently created environments. This verification is only applied to the default PyPI path and is skipped when custom indices are configured via `PIP INDEX URL`, `PIP EXTRA INDEX URL`, or `PIP INDEX`.
**Recommendations**
Update to version 21.7.12.