PT-2026-102924 · Pypi · Virtualenv
CVSS v4.0
7.7
High
| Vector | AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
virtualenv versions prior to 21.7.12
Description
The
download wheel() function fails to verify the bytes of pip and setuptools seed wheels fetched during periodic updates or via the --download option against an authoritative digest, unlike the BUNDLE SHA256 verification used for embedded wheels. This allows a compromised index, stale mirror, or intercepted TLS connection to substitute a malicious wheel under the requested distribution, version, and filename. Once substituted, the attacker-controlled wheel is cached and seeded into all subsequently created environments. This verification is only applied to the default PyPI path and is skipped when custom indices are configured via PIP INDEX URL, PIP EXTRA INDEX URL, or PIP INDEX.Recommendations
Update to version 21.7.12.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Virtualenv