Technology · PyPI
pip (PyPI) vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 14 vulnerabilities in pip (PyPI): 0 in the last 7 days and 4 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-13346, was published on 29 July 2026.
- Last 7 days
- 0
- Last 90 days
- 4
- Critical, all time
- 0
- Exploited in the wild
- 0
About pip (PyPI)
The standard package installer for Python.
Latest pip (PyPI) vulnerabilities
- CVE-2026-13346: PyPA pip path traversal via doubly-encoded package URLsmediumCVSS 4EPSS 0.3%
- CVE-2026-6357: PYSEC-2026-2876 - pip Vulnerable to Inclusion of Functionality from Untrusted Control SpheremediumCVSS 4EPSS 0.2%
- CVE-2026-1703: PYSEC-2026-1796 - pip Path Traversal vulnerabilitymediumCVSS 4EPSS 0.4%
- CVE-2025-8869: PYSEC-2026-1795 - pip's fallback tar extraction doesn't check symbolic links point to extraction directorymediumCVSS 4EPSS 0.5%
- CVE-2026-8643: Python pip path traversal via entry point scriptshighCVSS 8EPSS 0.5%
- CVE-2026-3219: PyPA pip interpretation conflict in concatenated archive handlingmediumCVSS 4EPSS 0.2%
- CVE-2023-5752: PYSEC-2023-228 - When installing a package from a Mercurial VCS URL (ie "pip install hg+...") with pip prior to v23.3, the…lowCVSS 3.1EPSS 0.5%
- CVE-2021-3572: PYSEC-2021-437 - A flaw was found in python-pip in the way it handled Unicode separators in git references. A remote…lowCVSS 3.1EPSS 1.8%
- CVE-2019-20916: PYSEC-2020-173 - The pip package before 19.2 for Python allows Directory Traversal when a URL is given in an install…lowCVSS 3.1EPSS 3.0%
- PYSEC-2020-192 - The pip package before 19.2 for Python allows Directory Traversal when a URL is given in an install command, because a…info
- CVE-2013-5123: PYSEC-2019-160 - The mirroring support (-M, --use-mirrors) in Python Pip before 1.5 uses insecure DNS querying and…lowCVSS 3.1EPSS 8.0%
- CVE-2014-8991: PYSEC-2014-11 - pip 1.3 through 1.5.6 allows local users to cause a denial of service (prevention of package installation)…lowCVSS 3.1EPSS 0.4%
- CVE-2013-1888: PYSEC-2013-9 - pip before 1.3 allows local users to overwrite arbitrary files via a symlink attack on a file in the…lowCVSS 3.1EPSS 0.4%
- CVE-2013-1629: PYSEC-2013-8 - pip before 1.3 uses HTTP to retrieve packages from the PyPI repository, and does not perform integrity…lowCVSS 3.1EPSS 6.2%
Most severe pip (PyPI) vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-8643: Python pip path traversal via entry point scriptshighCVSS 8EPSS 0.5%
- CVE-2025-8869: PYSEC-2026-1795 - pip's fallback tar extraction doesn't check symbolic links point to extraction directorymediumCVSS 4EPSS 0.5%
- CVE-2026-1703: PYSEC-2026-1796 - pip Path Traversal vulnerabilitymediumCVSS 4EPSS 0.4%
- CVE-2026-13346: PyPA pip path traversal via doubly-encoded package URLsmediumCVSS 4EPSS 0.3%
- CVE-2026-3219: PyPA pip interpretation conflict in concatenated archive handlingmediumCVSS 4EPSS 0.2%
- CVE-2026-6357: PYSEC-2026-2876 - pip Vulnerable to Inclusion of Functionality from Untrusted Control SpheremediumCVSS 4EPSS 0.2%
- CVE-2013-5123: PYSEC-2019-160 - The mirroring support (-M, --use-mirrors) in Python Pip before 1.5 uses insecure DNS querying and…lowCVSS 3.1EPSS 8.0%
- CVE-2013-1629: PYSEC-2013-8 - pip before 1.3 uses HTTP to retrieve packages from the PyPI repository, and does not perform integrity…lowCVSS 3.1EPSS 6.2%
- CVE-2019-20916: PYSEC-2020-173 - The pip package before 19.2 for Python allows Directory Traversal when a URL is given in an install…lowCVSS 3.1EPSS 3.0%
- CVE-2021-3572: PYSEC-2021-437 - A flaw was found in python-pip in the way it handled Unicode separators in git references. A remote…lowCVSS 3.1EPSS 1.8%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 2 | 0 | |
| 13 Jul 2026 | 1 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 1 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/pip.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "pip (PyPI) vulnerabilities", https://junglewise.ai/threats/technologies/pip, 26 September 2026.