PT-2026-2252 · Unknown+2 · Virtualenv+2

·

CVE-2026-22702

·

Published

2026-01-01

·

Updated

2026-07-09

CVSS v3.1

4.5

Medium

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions virtualenv versions prior to 20.36.1
Description virtualenv is a tool for creating isolated virtual python environments. Prior to version 20.36.1, Time-of-Check-Time-of-Use (TOCTOU) vulnerabilities exist in virtualenv that allow local attackers to perform symlink-based attacks on directory creation operations. An attacker with local access can exploit a race condition between directory existence checks and creation to redirect virtualenv's app data and lock file operations to attacker-controlled locations. The vulnerability affects the directory creation operations.
Recommendations Update virtualenv to version 20.36.1 or later.

Exploit

Fix

DoS

Race Condition

Link Following

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-74210
AZL-74237
BDU:2026-09807
BIT-VIRTUALENV-2026-22702
CVE-2026-22702
ECHO-BFF4-EEE0-85F1
GHSA-597G-3PHW-6986
OESA-2026-1185
OESA-2026-1186
OESA-2026-1187
OESA-2026-1188
OPENSUSE-SU-2026:10055-1
OPENSUSE-SU-2026:20086-1
PYSEC-2026-2009
SUSE-SU-2026:0233-1
SUSE-SU-2026:20129-1

Affected Products

Debian
Red Os
Virtualenv