CVE Tools

Pip

14 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Pip, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.

Pip CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Pip CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-010
2025-020
2025-030
2025-040
2025-050
2025-060
2025-070
2025-080
2025-091
2025-100
2025-110
2025-120
2026-010
2026-021
2026-030
2026-042
2026-050
2026-061
2026-071
2026-080
2026-090

Severity

How the 14 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • High217%
  • Medium758%
  • Low325%

Latest CVEs

The 14 most recently published vulnerabilities affecting Pip.

  1. CVE-2026-13346pip absolute path traversal during download from malicious package indexes6.5
  2. CVE-2026-8643pip can extract console_scripts and gui_scripts outside installation directory5.5
  3. CVE-2026-6357pip self-update functionality can import newly installed modules after wheel installation—
  4. CVE-2026-3219pip doesn't reject concatenated ZIP and tar archives—
  5. CVE-2026-1703Limited path traversal when installing wheel archives3.5
  6. CVE-2025-8869Fallback tar extraction in pip doesn't check symbolic links point to extraction directory5.7
  7. CVE-2023-5752Mercurial configuration injectable in repo revision when installing via pip5.5
  8. CVE-2021-3572A flaw was found in python-pip in the way it handled Unicode separators in git references. A remote attacker could possibly use this issue to install a different revision on a repository. The highe...5.7
  9. CVE-2019-20916The pip package before 19.2 for Python allows Directory Traversal when a URL is given in an install command, because a Content-Disposition header can have ../ in a filename, as demonstrated by over...7.5
  10. CVE-2018-20225An issue was discovered in pip (all versions) because it installs the version with the highest version number, even if the user had intended to obtain a private package from a private index. This o...7.8
  11. CVE-2013-5123The mirroring support (-M, --use-mirrors) in Python Pip before 1.5 uses insecure DNS querying and authenticity checks which allows attackers to perform man-in-the-middle attacks.5.9
  12. CVE-2014-8991pip 1.3 through 1.5.6 allows local users to cause a denial of service (prevention of package installation) by creating a /tmp/pip-build-* file for another user.2.1
  13. CVE-2013-1888pip before 1.3 allows local users to overwrite arbitrary files via a symlink attack on a file in the /tmp/pip-build temporary directory.2.1
  14. CVE-2013-1629pip before 1.3 uses HTTP to retrieve packages from the PyPI repository, and does not perform integrity checks on package contents, which allows man-in-the-middle attackers to execute arbitrary code...6.8

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store