CVE Tools

Pypa

3 CVEs tracked since 2013. Since Aug 2013, none of them reached CISA KEV.

Pypa CVEs per month

Aug 2013 to Nov 2014. Point at a month, or focus the strip and use the arrow keys.
Pypa CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2013-0820
2013-09null or fewer
2013-10null or fewer
2013-11null or fewer
2013-12null or fewer
2014-01null or fewer
2014-02null or fewer
2014-03null or fewer
2014-04null or fewer
2014-05null or fewer
2014-06null or fewer
2014-07null or fewer
2014-08null or fewer
2014-09null or fewer
2014-10null or fewer
2014-1110

Products

The products that kept showing up in Pypa's monthly top three, with their CVEs summed over those months.

  1. Pip32 months

Latest CVEs

The 15 most recently published vulnerabilities affecting Pypa.

  1. CVE-2026-13346pip absolute path traversal during download from malicious package indexes6.5
  2. CVE-2026-59890setuptools: MANIFEST.in exclusion bypass in sdist via Unicode normalization collision (NFC/NFD) on macOS APFS/HFS+6.1
  3. CVE-2026-8643pip can extract console_scripts and gui_scripts outside installation directory5.5
  4. CVE-2026-24049wheel Allows Arbitrary File Permission Modification via Path Traversal7.1
  5. CVE-2026-22702virtualenv Has TOCTOU Vulnerabilities in Directory Creation4.5
  6. CVE-2025-47273setuptools has a path traversal vulnerability in PackageIndex.download that leads to Arbitrary File Write8.8
  7. CVE-2024-6345Remote Code Execution in pypa/setuptools8.8
  8. CVE-2023-5752Mercurial configuration injectable in repo revision when installing via pip5.5
  9. CVE-2022-21668Pipenv's requirements.txt parsing allows malicious index url in comments8.0
  10. CVE-2021-3572A flaw was found in python-pip in the way it handled Unicode separators in git references. A remote attacker could possibly use this issue to install a different revision on a repository. The highe...5.7
  11. CVE-2019-20916The pip package before 19.2 for Python allows Directory Traversal when a URL is given in an install command, because a Content-Disposition header can have ../ in a filename, as demonstrated by over...7.5
  12. CVE-2018-20225An issue was discovered in pip (all versions) because it installs the version with the highest version number, even if the user had intended to obtain a private package from a private index. This o...7.8
  13. CVE-2013-5123The mirroring support (-M, --use-mirrors) in Python Pip before 1.5 uses insecure DNS querying and authenticity checks which allows attackers to perform man-in-the-middle attacks.5.9
  14. CVE-2014-8991pip 1.3 through 1.5.6 allows local users to cause a denial of service (prevention of package installation) by creating a /tmp/pip-build-* file for another user.2.1
  15. CVE-2013-1888pip before 1.3 allows local users to overwrite arbitrary files via a symlink attack on a file in the /tmp/pip-build temporary directory.2.1

The record

Peak rank
#53 in Aug 2013
Busiest month shown
Aug 2013, 2 CVEs
Months with a KEV entry
0 since Aug 2013
Monthly snapshots
2 since 2013
Pypa's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store