Skip to content

Update dependency pip to >=26.2,<26.3 [SECURITY] - #2264

Open
renovate[bot] wants to merge 1 commit into
masterfrom
renovate/pypi-pip-vulnerability
Open

Update dependency pip to >=26.2,<26.3 [SECURITY]#2264
renovate[bot] wants to merge 1 commit into
masterfrom
renovate/pypi-pip-vulnerability

Conversation

@renovate

@renovate renovate Bot commented Sep 1, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
pip (changelog) >=26.1.2,<26.2>=26.2,<26.3 age confidence

pip would incorrectly handle doubly-encoded package URLs from indexes

CVE-2026-13346 / GHSA-qwm4-qh6w-59xr

More information

Details

pip would incorrectly handle doubly-encoded package URLs from indexes allowing for files to be installed to arbitrary locations on disk even when installing wheels.

This vulnerability requires downloading or installing a package from a malicious package index to succeed, malicious packages alone are not able to exploit this vulnerability. Note that this vulnerability only materially impacts users running pip download with the --only-binary option as installing source distributions from an untrusted index is already an unsafe operation that executes code during install time.

Severity

  • CVSS Score: 5.6 / 10 (Medium)
  • Vector String: CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Release Notes

pypa/pip (pip)

v26.2

Compare Source


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot changed the title Update dependency pip to >=26.2,<26.3 [SECURITY] Update dependency pip to >=26.2.1,<26.3 [SECURITY] Sep 2, 2026
@renovate
renovate Bot force-pushed the renovate/pypi-pip-vulnerability branch from f2d4057 to ae0e33c Compare September 2, 2026 22:46
@renovate renovate Bot changed the title Update dependency pip to >=26.2.1,<26.3 [SECURITY] Update dependency pip to >=26.2,<26.3 [SECURITY] Sep 3, 2026
@renovate
renovate Bot force-pushed the renovate/pypi-pip-vulnerability branch from ae0e33c to 544c4ff Compare September 3, 2026 04:05
@renovate renovate Bot changed the title Update dependency pip to >=26.2,<26.3 [SECURITY] Update dependency pip to >=26.2.1,<26.3 [SECURITY] Sep 3, 2026
@renovate
renovate Bot force-pushed the renovate/pypi-pip-vulnerability branch from 544c4ff to 2bb9c50 Compare September 3, 2026 09:10
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
@renovate renovate Bot changed the title Update dependency pip to >=26.2.1,<26.3 [SECURITY] Update dependency pip to >=26.2,<26.3 [SECURITY] Sep 4, 2026
@renovate
renovate Bot force-pushed the renovate/pypi-pip-vulnerability branch from 2bb9c50 to c992e4f Compare September 4, 2026 02:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants