Known vulnerabilities in pip
Vendor:
Python Packaging Authority
Software:
pip
Software CPE:
cpe:2.3:a:pypa:pip:*:*:*:*:*:*:*:*
Website:
https://github.com/pypa/
Total vulnerabilities:
4
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
7.7
Breakdown by Severity Chart
26.2.1
26.2
26.1.2
26.1.1
26.1
26.0.1
26.0
25.3
25.2
25.1.1
25.1
25.0.1
25.0
24.3.1
24.3
24.2
24.1.2
24.1.1
24.1
24.0
23.3.2
23.3.1
23.3
23.2.1
23.2
23.1.2
23.1.1
23.1
23.0.1
23.0
22.3.1
22.3
22.2.2
22.2.1
22.2
22.1.2
22.1.1
22.1
22.0.4
22.0.3
22.0.2
22.0.1
22.0
21.3.1
21.3
21.2.4
21.2.3
21.2.2
21.2.1
21.2
21.1.3
21.1.2
21.1.1
21.1
21.0.1
21.0
20.3.4
20.3.3
20.3.2
20.3.1
20.3
20.2.4
20.2.3
20.2.2
20.2.1
20.2
20.1.1
20.1
20.0.2
20.0.1
20.0
19.3.1
19.3
19.2.3
19.2.2
19.2.1
19.2
19.1.1
19.1
19.0.3
19.0.2
19.0.1
19.0
18.1
18.0
10.0.1
10.0.0
9.0.3
9.0.2
9.0.1
9.0.0
8.1.2
8.1.1
8.1.0
8.0.3
8.0.2
8.0.1
8.0.0
7.1.2
7.1.1
7.1.0
7.0.3
7.0.2
7.0.1
7.0.0
6.1.1
6.1.0
6.0.8
6.0.7
6.0.6
6.0.5
6.0.4
6.0.3
6.0.2
6.0.1
6.0
1.5.6
1.5.5
1.5.4
1.5.3
1.5.2
1.5.1
1.5
1.4.1
1.4
1.3.1
1.3
1.2.1
1.2
1.1
1.0.2
1.0.1
1.0
0.8.3
0.8.2
0.8.1
0.8
0.7.2
0.7.1
0.7
0.6.1
0.6
0.5
0.4
0.3
Vulnerabilities (4)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU123468 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CVE-2026-1703 |
CWE-22 | Low | 26.0 | 03.03.2026 |
SB2026030336 SB2026030337 SB2026030338 and 8 more |
||
| #VU118203 - Improper Check for Unusual or Exceptional Conditions CVE-2025-8869 |
CWE-754 | Medium | 25.3 | 07.11.2025 |
SB2025110747 SB2025110755 SB2025112220 and 24 more |
||
| #VU88540 - Data Handling CVE-2018-20225 |
CWE-19 | Medium | - | 15.04.2024 |
SB2020050805 SB2024041561 SB2024041562 and 6 more |
||
| #VU84849 - Command injection CVE-2023-5752 |
CWE-77 | Medium | 23.3 | 28.12.2023 |
SB2023122824 SB2023122825 SB2023122826 and 32 more |