Skip to content

Update dependency pip to v26.2 [SECURITY] (1.22) - #3797

Merged
renovate[bot] merged 1 commit into
1.22from
renovate/1.22-pypi-pip-vulnerability
Aug 21, 2026
Merged

Update dependency pip to v26.2 [SECURITY] (1.22)#3797
renovate[bot] merged 1 commit into
1.22from
renovate/1.22-pypi-pip-vulnerability

Conversation

@renovate

@renovate renovate Bot commented Aug 21, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
pip (changelog) ==26.1.2==26.2 age confidence

CVE-2026-13346 / PYSEC-2026-3721

More information

Details

pip would incorrectly handle doubly-encoded package URLs from indexes allowing for files to be installed to arbitrary locations on disk even when installing wheels.

This vulnerability requires downloading or installing a package from a malicious package index to succeed, malicious packages alone are not able to exploit this vulnerability. Note that this vulnerability only materially impacts users running pip download with the --only-binary option as installing source distributions from an untrusted index is already an unsafe operation that executes code during install time.

Severity

  • CVSS Score: 6.5 / 10 (Medium)
  • Vector String: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

References

This data is provided by OSV and the PyPI Advisory Database (CC-BY 4.0).


Release Notes

pypa/pip (pip)

v26.2

Compare Source


Configuration

📅 Schedule: (in timezone Europe/Zurich)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot added the security Pull requests that address a security vulnerability label Aug 21, 2026
@renovate
renovate Bot enabled auto-merge (squash) August 21, 2026 13:25
@renovate
renovate Bot merged commit 781b767 into 1.22 Aug 21, 2026
10 checks passed
@renovate
renovate Bot deleted the renovate/1.22-pypi-pip-vulnerability branch August 21, 2026 13:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

security Pull requests that address a security vulnerability

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants