Junglewise Threat Intelligence

CVE-2025-13327: uv has ZIP payload obfuscation through parsing differentials

CVE-2025-13327 · Severity: medium · CVSS 4 · Published 2026-02-27

Vendors: crates.io, PyPI.

Executive brief

uv has ZIP payload obfuscation through parsing differentials

Affected products

  • crates.io uv
  • PyPI uv

Related threats