RHSA-2026:36315HighCVSS 8.0
Red Hat Security Advisory: python3.14-pip security update
🔗 CVE IDs covered (1)
📋 Description
CVE-2026-8643 — python-pip: Path traversal via malicious entry point name in pip wheel installation allows arbitrary file overwrite
🎯 Affected products4
- Red Hat Enterprise Linux AppStream (v. 9)
- python3.14-pip-0:25.2-3.el9_8.5.noarch as a component of Red Hat Enterprise Linux AppStream (v. 9)
- python3.14-pip-0:25.2-3.el9_8.5.src as a component of Red Hat Enterprise Linux AppStream (v. 9)
- python3.14-pip-wheel-0:25.2-3.el9_8.5.noarch as a component of Red Hat Enterprise Linux AppStream (v. 9)
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: To mitigate this issue, users should avoid installing Python wheels from untrusted sources. It is strongly advised against using `pip install` with elevated privileges, such as `sudo`, when installing wheels. Additionally, administrators should inspect `entry_points.txt` within wheels for path separators or absolute paths before installation.