Vulnerability PYSEC-2026-2295
Medium Risk
MEDIUM RISK
CVSS Score: 6.3
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
7 months ago
February 27, 2026 at 08:17 AM UTC
No summary available
0.0.5 - 0.9.5
0.0.5 - 0.9.5
Details
A flaw was found in uv. This vulnerability allows an attacker to execute malicious code during package resolution or installation via specially crafted ZIP (Zipped Information Package) archives that exploit parsing differentials, requiring user interaction to install an attacker-controlled package.
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Medium Risk
9 hours ago
uv: Path traversal on Windows through wheel extraction
0.12.7 - 0.12.17 GHSA-2cv4-cqwr-gwf7
0.12.7 - 0.12.17 GHSA-2cv4-cqwr-gwf7
Unknown
3 months ago
uv allows ZIP payload obfuscation through parsing differentials
0.0.5 - 0.8.5 PYSEC-2026-2001
0.0.5 - 0.8.5 PYSEC-2026-2001
Medium Risk
4 months ago
uv is vulnerable to arbitrary file write through entry point names
0.0.5 - 0.11.14 GHSA-4gg8-gxpx-9rph
0.0.5 - 0.11.14 GHSA-4gg8-gxpx-9rph
Low Risk
5 months ago
uv vulnerable to arbitrary file deletion through RECORD entries
0.0.5 - 0.11.5 GHSA-pjjw-68hj-v9mw
0.0.5 - 0.11.5 GHSA-pjjw-68hj-v9mw
Medium Risk
11 months ago
uv allows ZIP payload obfuscation through parsing differentials
0.0.5 - 0.9.5 GHSA-pqhf-p39g-3x64
0.0.5 - 0.9.5 GHSA-pqhf-p39g-3x64
Impacted packages
Timeline
Published
7 months ago
February 27, 2026 at 08:17 AM UTC
Fixed (0.9.6)
11 months ago
October 29, 2025 at 07:40 PM UTC
Last Modified
2 months ago
July 13, 2026 at 07:26 AM UTC