#VU121190 Time-of-check Time-of-use (TOCTOU) Race Condition in py3-virtualenv - CVE-2026-22702
Published: January 13, 2026
py3-virtualenv
www.virtualenv.org
Description
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a race condition between directory existence checks and creation to redirect virtualenv's app_data and lock file operations to attacker-controlled locations. A local user can gain access to sensitive information, poison cache or perform a denial of service attack.