RHSA-2026:37283HighCVSS 8.0
Red Hat Security Advisory: RHTAS 1.4 - GA Release of Model Transparency 1.0.2
🔗 CVE IDs covered (1)
📋 Description
CVE-2026-8643 — python-pip: Path traversal via malicious entry point name in pip wheel installation allows arbitrary file overwrite
🔗 References (6)
- selfhttps://access.redhat.com/errata/RHSA-2026:37283
- externalhttps://access.redhat.com/documentation/en-us/red_hat_trusted_artifact_signer/1.4
- externalhttps://access.redhat.com/documentation/en-us/red_hat_trusted_artifact_signer/1.4/html-single/release_notes/index
- externalhttps://access.redhat.com/security/cve/CVE-2026-8643
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_37283.json