RHSA-2026:36315HighCVSS 8.0

Red Hat Security Advisory: python3.14-pip security update

Published
July 7, 2026
Last Modified
August 2, 2026

🔗 CVE IDs covered (1)

📋 Description

CVE-2026-8643 — python-pip: Path traversal via malicious entry point name in pip wheel installation allows arbitrary file overwrite

🎯 Affected products4

  • Red Hat Enterprise Linux AppStream (v. 9)
  • python3.14-pip-0:25.2-3.el9_8.5.noarch as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • python3.14-pip-0:25.2-3.el9_8.5.src as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • python3.14-pip-wheel-0:25.2-3.el9_8.5.noarch as a component of Red Hat Enterprise Linux AppStream (v. 9)

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: To mitigate this issue, users should avoid installing Python wheels from untrusted sources. It is strongly advised against using `pip install` with elevated privileges, such as `sudo`, when installing wheels. Additionally, administrators should inspect `entry_points.txt` within wheels for path separators or absolute paths before installation.

🔗 References (4)