
CVE-2026-3219: pip doesn't reject concatenated ZIP and tar archives https://www.openwall.com/lists/oss-security/2026/04/20/8 handles them as ZIP files regardless of filename or whether a file is both a tar and ZIP file. This could result in installing "incorrect" files according to the filename of the archive.
Post summary
The post announces the CVE‑2026‑3219 vulnerability, describing how pip incorrectly treats concatenated ZIP and tar archives as ZIP files, potentially leading to installation of wrong files.


