PT-2026-33775 · Pypi+1 · Pip+1

CVE-2026-3219

·

Published

2026-03-26

·

Updated

2026-09-04

CVSS v3.1

5.0

Medium

VectorAV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions pip (affected versions not specified)
Description pip processes concatenated tar and ZIP files exclusively as ZIP files, ignoring the filename or the fact that the file contains both archive types. This behavior can lead to the installation of incorrect files based on the archive's filename.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-83184
AZL-83432
BDU:2026-09330
CLEANSTART-2026-DD95169
CLEANSTART-2026-NN42198
CLEANSTART-2026-NR60332
CLEANSTART-2026-SA70432
CLEANSTART-2026-SY44974
CLEANSTART-2026-UC45646
CLEANSTART-2026-YC81398
CLEANSTART-2026-ZO99127
CVE-2026-3219
ECHO-E9F8-2DCB-3BE1
GHSA-58QW-9MGM-455V
OESA-2026-2360
OESA-2026-2361
OESA-2026-2362
OESA-2026-2363
OESA-2026-2497
OPENSUSE-SU-2026:10645-1
OPENSUSE-SU-2026:11690-1
OPENSUSE-SU-2026:20880-1
PYSEC-2026-2875
RHSA-2026:20074
RHSA-2026:36359
SUSE-SU-2026:22018-1
SUSE-SU-2026:2387-1
SUSE-SU-2026:2634-1
SUSE-SU-2026:2664-1
SUSE-SU-2026:2758-1
SUSE-SU-2026:3601-1
SUSE-SU-2026:3635-1
SUSE-SU-2026:3649-1
SUSE-SU-2026:3855-1
SUSE-SU-2026:3862-1

Affected Products

Red Os
Pip