| Bug | bullseye | bookworm | trixie | forky | sid | Description |
|---|
| CVE-2026-8643 | vulnerable | vulnerable | vulnerable | vulnerable | vulnerable | |
| CVE-2026-6357 | vulnerable (no DSA, postponed) | vulnerable (no DSA) | vulnerable (no DSA) | fixed | fixed | pip prior to version 26.1 would run self-update check functionality af ... |
| CVE-2026-3219 | vulnerable (no DSA, postponed) | vulnerable (no DSA) | vulnerable (no DSA) | fixed | fixed | pip handles concatenated tar and ZIP files as ZIP files regardless of ... |
| CVE-2026-1703 | vulnerable (no DSA, postponed) | vulnerable (no DSA) | vulnerable (no DSA) | fixed | fixed | When pip is installing and extracting a maliciously crafted wheel arch ... |
| CVE-2025-8869 | fixed | vulnerable (no DSA) | vulnerable (no DSA) | fixed | fixed | When extracting a tar archive pip may not check symbolic links point i ... |
| CVE-2023-5752 | fixed | vulnerable (no DSA) | fixed | fixed | fixed | When installing a package from a Mercurial VCS URL (ie "pip install ... |