{"schema_version":"1.7.5","id":"openSUSE-SU-2026:20880-1","published":"2026-06-02T13:37:18Z","modified":"2026-06-04T09:00:10.504857044Z","related":["CVE-2026-1703","CVE-2026-3219","CVE-2026-6357"],"upstream":["CVE-2026-1703","CVE-2026-3219","CVE-2026-6357"],"summary":"Security update for python-pip","details":"This update for python-pip fixes the following issues:\n\n- CVE-2026-3219: concatenated tar and ZIP files are handled as ZIP files, resulting in possibly obfuscated malicious\n  code (bsc#1262429).\n- CVE-2026-6357: pip self-update functionality can import newly installed modules after wheel installation, resulting\n  in potential arbitrary code execution (bsc#1263442).\n","references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262429"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263442"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-1703"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-3219"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-6357"}]}