CVE-2026-3219Disclosure

LOWCVSS 4.6 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

pip handles concatenated tar and ZIP files as ZIP files regardless of filename or whether a file is both a tar and ZIP file. This behavior could result in confusing installation behavior, such as installing "incorrect" files according to the filename of the archive. New behavior only proceeds with installation if the file identifies uniquely as a ZIP or tar archive, not as both.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-434

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-04-20); latest day: 1
  • 3 total mentions across 3 days

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-04-20: 1Mentions · 2026-04-21: 1Mentions · 2026-04-25: 1Technical Details · 2026-04-20: 1Technical Details · 2026-04-21: 104-2004-2104-25
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-04-201
Disclosure1
2026-04-211
Disclosure1
2026-04-251
General1
Full discourse3 posts
  • Open Source Security mailing list@oss_security
    Disclosure

    CVE-2026-3219: pip doesn't reject concatenated ZIP and tar archives https://www.openwall.com/lists/oss-security/2026/04/20/8 handles them as ZIP files regardless of filename or whether a file is both a tar and ZIP file. This could result in installing "incorrect" files according to the filename of the archive.

    Post summary

    The post announces the CVE‑2026‑3219 vulnerability, describing how pip incorrectly treats concatenated ZIP and tar archives as ZIP files, potentially leading to installation of wrong files.

    01052499
    4.7K followersView on X
  • Rhiyddun@rhiyddun
    General

    Winston, I realize you seem to primarily work with Windoze, but I had a slight panic attack here, ran a periodic pip-audit and got this disturbing line: Name     Version ID             Fix Versions -------- ------- -------------- ------------ pip      26.0.1  CVE-2026-3219 as in no fix at the moment??? pip??? You got the latest & greatest info on this?

    Post summary

    The user reports a CVE (CVE‑2026‑3219) affecting pip 26.0.1, noting that no fix is currently available and requests updated information.

    1000066
    1.2K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-3219 pip handles concatenated tar and ZIP files as ZIP files regardless of filename or whether a file is both a tar and ZIP file. This behavior could result in confusing ins… https://www.cve.org/CVERecord?id=CVE-2026-3219

    Post summary

    The excerpt provides a brief technical disclosure of CVE-2026-3219, describing how pip mishandles concatenated tar and ZIP files, but contains no PoC, exploit, or mitigation information.

    0000099
    57.2K followersView on X

Explore more