Logo
vulnerabilityCVE-2026-3219
Name
CVE-2026-3219
Source
NVD ( link)Debian ( link)
Description
pip handles concatenated tar and ZIP files as ZIP files regardless of filename or whether a file is both a tar and ZIP file. This behavior could result in confusing installation behavior, such as installing "incorrect" files according to the filename of the archive. New behavior only proceeds with installation if the file identifies uniquely as a ZIP or tar archive, not as both.
Published Date
Updated Date
Workaround
-
Advisories

Analysis#


Affected Component
Analysis
python-pip
Exploitable

Vulnerability Ratings#


4.6
CVSSv4
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
master
26.1
Not Affected
openwrt
master
26.2.1-r1
Not Affected
openwrt
openwrt-25.12
23.3.1-r2
Exploitable
yocto
master
26.2
Not Affected