UBUNTU-CVE-2026-59890

Source
https://ubuntu.com/security/CVE-2026-59890
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-59890.json
JSON Data
https://api.test.osv.dev/v1/vulns/UBUNTU-CVE-2026-59890
Upstream
Published
2026-07-08T17:17:00Z
Modified
2026-07-15T19:47:05.896246456Z
Severity
  • 6.1 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N CVSS Calculator
  • Ubuntu - medium
Summary
[none]
Details

setuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. Prior to 83.0.0, FileList applied MANIFEST.in exclude, global-exclude, recursive-exclude, and prune directives by matching compiled glob patterns against on-disk file names without Unicode normalization, so on macOS APFS or HFS+ an NFD file name could bypass an NFC exclusion rule and be packed into a source distribution. This issue is fixed in version 83.0.0.

References

Affected packages

Ubuntu:20.04:LTS / setuptools

Package

Name
setuptools
Purl
pkg:deb/ubuntu/setuptools?arch=source&distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

45.*
45.2.0-1
45.2.0-1ubuntu0.1
45.2.0-1ubuntu0.2
45.2.0-1ubuntu0.3

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "45.2.0-1ubuntu0.3",
            "binary_name": "python3-pkg-resources"
        },
        {
            "binary_version": "45.2.0-1ubuntu0.3",
            "binary_name": "python3-setuptools"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-59890.json"

Ubuntu:22.04:LTS / setuptools

Package

Name
setuptools
Purl
pkg:deb/ubuntu/setuptools?arch=source&distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

52.*
52.0.0-4
58.*
58.2.0-1
59.*
59.6.0-1.2
59.6.0-1.2ubuntu0.22.04.1
59.6.0-1.2ubuntu0.22.04.2
59.6.0-1.2ubuntu0.22.04.3

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "59.6.0-1.2ubuntu0.22.04.3",
            "binary_name": "python3-pkg-resources"
        },
        {
            "binary_version": "59.6.0-1.2ubuntu0.22.04.3",
            "binary_name": "python3-setuptools"
        },
        {
            "binary_version": "59.6.0-1.2ubuntu0.22.04.3",
            "binary_name": "python3-setuptools-whl"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-59890.json"

Ubuntu:24.04:LTS / setuptools

Package

Name
setuptools
Purl
pkg:deb/ubuntu/setuptools?arch=source&distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

68.*
68.1.2-2
68.1.2-2ubuntu1
68.1.2-2ubuntu1.1
68.1.2-2ubuntu1.2

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "68.1.2-2ubuntu1.2",
            "binary_name": "python3-pkg-resources"
        },
        {
            "binary_version": "68.1.2-2ubuntu1.2",
            "binary_name": "python3-setuptools"
        },
        {
            "binary_version": "68.1.2-2ubuntu1.2",
            "binary_name": "python3-setuptools-whl"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-59890.json"

Ubuntu:25.10 / setuptools

Package

Name
setuptools
Purl
pkg:deb/ubuntu/setuptools?arch=source&distro=questing

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

75.*
75.8.0-1
78.*
78.1.0-1.2
78.1.1-0.1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "78.1.1-0.1",
            "binary_name": "python3-pkg-resources"
        },
        {
            "binary_version": "78.1.1-0.1",
            "binary_name": "python3-setuptools"
        },
        {
            "binary_version": "78.1.1-0.1",
            "binary_name": "python3-setuptools-whl"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-59890.json"

Ubuntu:26.04:LTS / setuptools

Package

Name
setuptools
Purl
pkg:deb/ubuntu/setuptools?arch=source&distro=resolute

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

78.*
78.1.1-0.1
78.1.1-0.1build1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "78.1.1-0.1build1",
            "binary_name": "python3-pkg-resources"
        },
        {
            "binary_version": "78.1.1-0.1build1",
            "binary_name": "python3-setuptools"
        },
        {
            "binary_version": "78.1.1-0.1build1",
            "binary_name": "python3-setuptools-whl"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-59890.json"