OESA-2026-2360

Source
https://www.openeuler.org/en/security/security-bulletins/detail/?id=openEuler-SA-2026-2360
Import Source
https://repo.openeuler.org/security/data/osv/OESA-2026-2360.json
JSON Data
https://api.osv.dev/v1/vulns/OESA-2026-2360
Upstream
  • CVE-2026-3219
Published
2026-05-22T13:16:55Z
Modified
2026-05-22T13:30:10.320594559Z
Summary
python-pip security update
Details

%changelog * Thu Apr 9 2026 yixiangzhike <yixiangzhike007@163.com> - 23.3.1-10 - Fix CVE-2026-25645

Security Fix(es):

pip handles concatenated tar and ZIP files as ZIP files regardless of filename or whether a file is both a tar and ZIP file. This behavior could result in confusing installation behavior, such as installing "incorrect" files according to the filename of the archive. New behavior only proceeds with installation if the file identifies uniquely as a ZIP or tar archive, not as both.(CVE-2026-3219)

Database specific
{
    "severity": "Medium"
}
References

Affected packages

openEuler:24.03-LTS / python-pip

Package

Name
python-pip
Purl
pkg:rpm/openEuler/python-pip&distro=openEuler-24.03-LTS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
23.3.1-11.oe2403

Ecosystem specific

{
    "src": [
        "python-pip-23.3.1-11.oe2403.src.rpm"
    ],
    "noarch": [
        "python-pip-help-23.3.1-11.oe2403.noarch.rpm",
        "python-pip-wheel-23.3.1-11.oe2403.noarch.rpm",
        "python3-pip-23.3.1-11.oe2403.noarch.rpm"
    ]
}

Database specific

source
"https://repo.openeuler.org/security/data/osv/OESA-2026-2360.json"