https://seclists.org/oss-sec/2026/q2/188: Fwd: [CVE-2026-3219] pip doesn't ject concatenated ZIP and tar archives
Published Apr 20, 2026
·Updated
Affected Software
1 affected component
pypi/pip
Frequently Asked Questions
1
What is the severity of CVE-2026-3219?
CVE-2026-3219 has a medium severity rating.
2
How do I fix CVE-2026-3219?
To fix CVE-2026-3219, update pip to the latest version.
3
What type of vulnerability is CVE-2026-3219?
CVE-2026-3219 involves issues with how pip handles concatenated ZIP and tar archives.
4
Who is affected by CVE-2026-3219?
Users of pip who utilize concatenated ZIP and tar archives are affected by CVE-2026-3219.
5
What can happen if CVE-2026-3219 is exploited?
Exploitation of CVE-2026-3219 could lead to incorrect handling of archive files, potentially causing unauthorized file access.