GHSA-58qw-9mgm-455v

Suggest an improvement
Source
https://github.com/advisories/GHSA-58qw-9mgm-455v
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-58qw-9mgm-455v/GHSA-58qw-9mgm-455v.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-58qw-9mgm-455v
Aliases
  • CVE-2026-3219
Downstream
Related
Published
2026-04-20T18:31:48Z
Modified
2026-04-27T02:00:10.026458745Z
Severity
  • 4.6 (Medium) CVSS_V4 - CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
pip has an interpretation conflict due to handling both concatenated tar and ZIP files as ZIP files
Details

pip handles concatenated tar and ZIP files as ZIP files regardless of filename or whether a file is both a tar and ZIP file. This behavior could result in confusing installation behavior, such as installing "incorrect" files according to the filename of the archive. New behavior only proceeds with installation if the file identifies uniquely as a ZIP or tar archive, not as both.

Database specific
{
    "severity": "MODERATE",
    "github_reviewed": true,
    "nvd_published_at": "2026-04-20T16:16:45Z",
    "cwe_ids": [
        "CWE-434"
    ],
    "github_reviewed_at": "2026-04-24T15:48:17Z"
}
References

Affected packages

PyPI / pip

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
26.0.1

Affected versions

0.*
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.*
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1
1.3
1.3.1
1.4
1.4.1
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
6.*
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.1.0
6.1.1
7.*
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.1.2
8.*
8.0.0
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
8.1.2
9.*
9.0.0
9.0.1
9.0.2
9.0.3
10.*
10.0.0b1
10.0.0b2
10.0.0
10.0.1
18.*
18.0
18.1
19.*
19.0
19.0.1
19.0.2
19.0.3
19.1
19.1.1
19.2
19.2.1
19.2.2
19.2.3
19.3
19.3.1
20.*
20.0
20.0.1
20.0.2
20.1b1
20.1
20.1.1
20.2b1
20.2
20.2.1
20.2.2
20.2.3
20.2.4
20.3b1
20.3
20.3.1
20.3.2
20.3.3
20.3.4
21.*
21.0
21.0.1
21.1
21.1.1
21.1.2
21.1.3
21.2
21.2.1
21.2.2
21.2.3
21.2.4
21.3
21.3.1
22.*
22.0
22.0.1
22.0.2
22.0.3
22.0.4
22.1b1
22.1
22.1.1
22.1.2
22.2
22.2.1
22.2.2
22.3
22.3.1
23.*
23.0
23.0.1
23.1
23.1.1
23.1.2
23.2
23.2.1
23.3
23.3.1
23.3.2
24.*
24.0
24.1b1
24.1b2
24.1
24.1.1
24.1.2
24.2
24.3
24.3.1
25.*
25.0
25.0.1
25.1
25.1.1
25.2
25.3
26.*
26.0
26.0.1

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-58qw-9mgm-455v/GHSA-58qw-9mgm-455v.json"