{"id":"CVE-2026-102930","summary":"virtualenv: Downloaded seed wheels (pip/setuptools) are not integrity-checked before use","details":"virtualenv is a tool for creating isolated virtual python environments. Prior to 21.7.12, download_wheel() accepts pip and setuptools seed wheels fetched for periodic updates or the --download option without checking their bytes against an authoritative digest equivalent to the embedded wheels' BUNDLE_SHA256 verification. A compromised index, stale mirror, or intercepted TLS connection can substitute a different wheel under the requested distribution, version, and filename, after which virtualenv caches and seeds the attacker-controlled wheel into subsequently created environments. The verification applies to the default PyPI path and is intentionally skipped when PIP_INDEX_URL, PIP_EXTRA_INDEX_URL, or PIP_INDEX configures a custom index that may legitimately publish rebuilt wheels. This issue is fixed in version 21.7.12.","aliases":["GHSA-94p9-xgh2-xp45","PYSEC-2026-4011"],"modified":"2026-10-02T03:30:28.303212745Z","published":"2026-09-29T20:53:36.018Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-494"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/102xxx/CVE-2026-102930.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/102xxx/CVE-2026-102930.json"},{"type":"ADVISORY","url":"https://github.com/pypa/virtualenv/security/advisories/GHSA-94p9-xgh2-xp45"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-102930"},{"type":"FIX","url":"https://github.com/pypa/virtualenv/commit/a01ed3e2f239d6ab1fce62c5c7664ccf268fff6d"},{"type":"FIX","url":"https://github.com/pypa/virtualenv/pull/3251"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/pypa/virtualenv","events":[{"introduced":"0"},{"fixed":"a01ed3e2f239d6ab1fce62c5c7664ccf268fff6d"}],"database_specific":{"source":["AFFECTED_FIELD","REFERENCES"],"extracted_events":[{"introduced":"0"},{"fixed":"21.7.12"}]}}],"versions":["21.7.11","21.7.10","21.7.9","21.7.8","21.7.7","21.7.6","21.7.5","21.7.4","21.7.3","21.7.2","21.7.1","21.7.0","21.6.1","21.6.0","21.5.2","21.5.1","21.5.0","21.4.3","21.4.2","21.4.1","21.4.0","21.3.3","21.3.2","21.3.1","21.3.0","21.2.4","21.2.3","21.2.2","21.2.1","21.2.0","21.1.0","21.0.0","20.39.1","20.39.0","20.38.0","20.37.0","20.27.3","20.27.2","20.24.3","20.3.0","20.0.32","20.0.7","20.0.0b2","20.0.0b1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-102930.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}]}