PT-2026-56503 · Pypi+1 · Setuptools+1

·

CVE-2026-59890

·

Published

2026-07-08

·

Updated

2026-08-17

CVSS v3.1

6.1

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions setuptools versions prior to 83.0.0
Description setuptools is a package used to download, build, install, upgrade, and uninstall Python packages. The FileList component fails to perform Unicode normalization when matching compiled glob patterns against on-disk file names for MANIFEST.in exclude, global-exclude, recursive-exclude, and prune directives. On macOS APFS or HFS+ file systems, a file name using NFD (Normalization Form Decomposed) can bypass an NFC (Normalization Form Composed) exclusion rule, resulting in the file being unintentionally included in a source distribution.
Recommendations Update setuptools to version 83.0.0.

Exploit

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-92229
BIT-SETUPTOOLS-2026-59890
CVE-2026-59890
ECHO-732C-D358-5FEF
GHSA-H35F-9H28-MQ5C
OESA-2026-3191
PYSEC-2026-3447
RHSA-2026:37530

Affected Products

Red Os
Setuptools