ECHO-072a-9ff7-3371

See a problem?
Import Source
https://advisory.echohq.com/osv/ECHO-072a-9ff7-3371.json
JSON Data
https://api.osv.dev/v1/vulns/ECHO-072a-9ff7-3371
Upstream
  • CVE-2018-20225
  • GHSA-7p5p-7qq5-cc86
Withdrawn
2026-05-20T14:45:03Z
Published
2025-09-15T01:09:14Z
Modified
2026-09-15T03:42:47Z
Summary
Disputed by NVD and pip upstream. The CVE describes pip's --extra-index-url behavior where the highest version number is installed regardless of which index it comes from. The pip team considers this intended functionality, not a security flaw. Red Hat closed as WONTFIX; Ubuntu priority: Negligible. Affects all pip versions with no fix planned.
Details
References

Affected packages

Echo:PyPI / pip

Package

Name
pip
Purl
pkg:pypi/pip

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
25.2

Database specific

source
"https://advisory.echohq.com/osv/ECHO-072a-9ff7-3371.json"

Echo / python-3.11

Package

Name
python-3.11
Purl
pkg:deb/echo/python-3.11

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.11.15+e4

Database specific

source
"https://advisory.echohq.com/osv/ECHO-072a-9ff7-3371.json"

Echo / python-pip

Package

Name
python-pip
Purl
pkg:deb/echo/python-pip

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Database specific

source
"https://advisory.echohq.com/osv/ECHO-072a-9ff7-3371.json"