{"id":"AZL-92229","summary":"CVE-2026-59890 affecting package python-setuptools for versions less than 69.0.3-6","details":"setuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. Prior to 83.0.0, FileList applied MANIFEST.in exclude, global-exclude, recursive-exclude, and prune directives by matching compiled glob patterns against on-disk file names without Unicode normalization, so on macOS APFS or HFS+ an NFD file name could bypass an NFC exclusion rule and be packed into a source distribution. This issue is fixed in version 83.0.0.","modified":"2026-08-31T05:26:27Z","published":"2026-07-08T17:17:27Z","upstream":["CVE-2026-59890"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-59890"}],"affected":[{"package":{"name":"python-setuptools","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/python-setuptools"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"69.0.3-6"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-92229.json"}}],"schema_version":"1.9.0"}