Dependency Installation Vulnerability in Virtualenv by Python Software Foundation
CVE-2026-102930

7.7HIGH

Key Information:

Vendor

Pypa

Vendor
CVE Published:
29 September 2026

What is CVE-2026-102930?

The virtualenv tool, essential for creating isolated Python environments, contains a vulnerability prior to version 21.7.12. The issue lies in the download_wheel() function, which fails to verify the integrity of downloaded pip and setuptools seed wheels against an authoritative digest. This oversight opens the door for potential attacks via compromised package indexes, stale mirrors, or intercepted TLS connections, allowing an attacker to insert malicious wheels into the installation process. This vulnerability is not triggered when using custom indexes but poses a significant risk to users relying on default settings. The flaw has been addressed in version 21.7.12, emphasizing the importance of keeping software updated.

Affected Version(s)

virtualenv < 21.7.12

References

CVSS V4

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.