CVE-2026-3219
pip handles concatenated tar and ZIP files as ZIP files regardless of filename or whether a file is both a tar and ZIP file. This behavior could result in confusing installation behavior, such as installing "incorrect" files according to the filename of the archive. New behavior only proceeds with installation if the file identifies uniquely as a ZIP or tar archive, not as both.
- CVSS 4.0
- 4.6 MEDIUM
- EPSS
- 0.1% (4th percentile)
- Weakness
- CWE-434
- NVD status
- Awaiting Analysis
- Published
- 2026-04-20
CVE-2026-3219 at NVD
No indexed exploits for CVE-2026-3219 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2026-3219 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.