openSUSE-SU-2026:20880-1

See a problem?
Import Source
https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:20880-1.json
JSON Data
https://api.test.osv.dev/v1/vulns/openSUSE-SU-2026:20880-1
Upstream
CVE (3)
Related
Published
2026-06-02T13:37:18Z
Modified
2026-06-04T18:24:16Z
Summary
Security update for python-pip
Details

This update for python-pip fixes the following issues:

  • CVE-2026-3219: concatenated tar and ZIP files are handled as ZIP files, resulting in possibly obfuscated malicious code (bsc#1262429).
  • CVE-2026-6357: pip self-update functionality can import newly installed modules after wheel installation, resulting in potential arbitrary code execution (bsc#1263442).
References

Affected packages