pkg:PyPI/pip
18 total CVEsHIGH4MEDIUM10
✅ Check your installed version
All known vulnerabilities
- from 0, < 1.3
- from 0, < 1.3
- from 0, < 19.2
- from 0, < a4c735b14a62f9cb864533808ac63936704f2ace | from 0, < 19.2
- from 0, < 1.3
- >= 1.3, < 6.0
- >= 1.3, < 6.0
- from 0, < 1.3
- from 0, < 1.5
- from 0, < 1.5
- from 0, < 21.1
- from 0, < 21.1
- from 0, < 23.3
- from 0, < 23.3
- from 0, < 26.1
- —CVE-2026-3219pip has an interpretation conflict due to handling both concatenated tar and ZIP files as ZIP filesfrom 0, < 26.1
- from 0, < 26.0
- —CVE-2025-8869pip's fallback tar extraction doesn't check symbolic links point to extraction directoryfrom 0, < 25.3