PT-2026-102924 · Pypi · Virtualenv

·

CVE-2026-102930

·

Published

2026-09-29

·

Updated

2026-09-29

CVSS v4.0

7.7

High

VectorAV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions virtualenv versions prior to 21.7.12
Description The download wheel() function fails to verify the bytes of pip and setuptools seed wheels fetched during periodic updates or via the --download option against an authoritative digest, unlike the BUNDLE SHA256 verification used for embedded wheels. This allows a compromised index, stale mirror, or intercepted TLS connection to substitute a malicious wheel under the requested distribution, version, and filename. Once substituted, the attacker-controlled wheel is cached and seeded into all subsequently created environments. This verification is only applied to the default PyPI path and is skipped when custom indices are configured via PIP INDEX URL, PIP EXTRA INDEX URL, or PIP INDEX.
Recommendations Update to version 21.7.12.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-102930
GHSA-94P9-XGH2-XP45

Affected Products

Virtualenv