Skip to content

Update dependency pip to v26.1 [SECURITY]#1902

Merged
renovate[bot] merged 1 commit intomasterfrom
renovate/pypi-pip-vulnerability
Apr 27, 2026
Merged

Update dependency pip to v26.1 [SECURITY]#1902
renovate[bot] merged 1 commit intomasterfrom
renovate/pypi-pip-vulnerability

Conversation

@renovate
Copy link
Copy Markdown
Contributor

@renovate renovate Bot commented Apr 26, 2026

This PR contains the following updates:

Package Update Change OpenSSF
pip (changelog) minor ==26.0==26.1 OpenSSF Scorecard

pip has an interpretation conflict due to handling both concatenated tar and ZIP files as ZIP files

CVE-2026-3219 / GHSA-58qw-9mgm-455v

More information

Details

pip handles concatenated tar and ZIP files as ZIP files regardless of filename or whether a file is both a tar and ZIP file. This behavior could result in confusing installation behavior, such as installing "incorrect" files according to the filename of the archive. New behavior only proceeds with installation if the file identifies uniquely as a ZIP or tar archive, not as both.

Severity

  • CVSS Score: 4.6 / 10 (Medium)
  • Vector String: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N

References

This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).


Release Notes

pypa/pip (pip)

v26.1

Compare Source

v26.0.1

Compare Source


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • ""
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot enabled auto-merge (squash) April 26, 2026 22:18
@renovate renovate Bot temporarily deployed to Vespa Cloud CD April 26, 2026 22:18 Inactive
@renovate renovate Bot force-pushed the renovate/pypi-pip-vulnerability branch from 4324211 to 51df88c Compare April 27, 2026 02:21
@renovate renovate Bot temporarily deployed to Vespa Cloud CD April 27, 2026 02:22 Inactive
@renovate renovate Bot force-pushed the renovate/pypi-pip-vulnerability branch from 51df88c to 7ff7d8d Compare April 27, 2026 10:38
@renovate renovate Bot temporarily deployed to Vespa Cloud CD April 27, 2026 10:39 Inactive
@renovate renovate Bot merged commit fa24e73 into master Apr 27, 2026
9 checks passed
@renovate renovate Bot deleted the renovate/pypi-pip-vulnerability branch April 27, 2026 10:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants