{"id":"UBUNTU-CVE-2026-59890","details":"setuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. Prior to 83.0.0, FileList applied MANIFEST.in exclude, global-exclude, recursive-exclude, and prune directives by matching compiled glob patterns against on-disk file names without Unicode normalization, so on macOS APFS or HFS+ an NFD file name could bypass an NFC exclusion rule and be packed into a source distribution. This issue is fixed in version 83.0.0.","modified":"2026-07-15T19:47:52.096310940Z","published":"2026-07-08T17:17:00Z","upstream":["CVE-2026-59890"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-59890"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2026-59890"},{"type":"REPORT","url":"https://github.com/pypa/setuptools/security/advisories/GHSA-h35f-9h28-mq5c"}],"affected":[{"package":{"name":"setuptools","ecosystem":"Ubuntu:20.04:LTS","purl":"pkg:deb/ubuntu/setuptools?arch=source&distro=focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["45.2.0-1","45.2.0-1ubuntu0.1","45.2.0-1ubuntu0.2","45.2.0-1ubuntu0.3"],"ecosystem_specific":{"binaries":[{"binary_name":"python3-pkg-resources","binary_version":"45.2.0-1ubuntu0.3"},{"binary_version":"45.2.0-1ubuntu0.3","binary_name":"python3-setuptools"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-59890.json"}},{"package":{"name":"setuptools","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/setuptools?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["52.0.0-4","58.2.0-1","59.6.0-1.2","59.6.0-1.2ubuntu0.22.04.1","59.6.0-1.2ubuntu0.22.04.2","59.6.0-1.2ubuntu0.22.04.3"],"ecosystem_specific":{"binaries":[{"binary_name":"python3-pkg-resources","binary_version":"59.6.0-1.2ubuntu0.22.04.3"},{"binary_name":"python3-setuptools","binary_version":"59.6.0-1.2ubuntu0.22.04.3"},{"binary_version":"59.6.0-1.2ubuntu0.22.04.3","binary_name":"python3-setuptools-whl"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-59890.json"}},{"package":{"name":"setuptools","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/setuptools?arch=source&distro=noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["68.1.2-2","68.1.2-2ubuntu1","68.1.2-2ubuntu1.1","68.1.2-2ubuntu1.2"],"ecosystem_specific":{"binaries":[{"binary_name":"python3-pkg-resources","binary_version":"68.1.2-2ubuntu1.2"},{"binary_name":"python3-setuptools","binary_version":"68.1.2-2ubuntu1.2"},{"binary_version":"68.1.2-2ubuntu1.2","binary_name":"python3-setuptools-whl"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-59890.json"}},{"package":{"name":"setuptools","ecosystem":"Ubuntu:25.10","purl":"pkg:deb/ubuntu/setuptools?arch=source&distro=questing"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["75.8.0-1","78.1.0-1.2","78.1.1-0.1"],"ecosystem_specific":{"binaries":[{"binary_name":"python3-pkg-resources","binary_version":"78.1.1-0.1"},{"binary_name":"python3-setuptools","binary_version":"78.1.1-0.1"},{"binary_name":"python3-setuptools-whl","binary_version":"78.1.1-0.1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-59890.json"}},{"package":{"name":"setuptools","ecosystem":"Ubuntu:26.04:LTS","purl":"pkg:deb/ubuntu/setuptools?arch=source&distro=resolute"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["78.1.1-0.1","78.1.1-0.1build1"],"ecosystem_specific":{"binaries":[{"binary_version":"78.1.1-0.1build1","binary_name":"python3-pkg-resources"},{"binary_name":"python3-setuptools","binary_version":"78.1.1-0.1build1"},{"binary_version":"78.1.1-0.1build1","binary_name":"python3-setuptools-whl"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-59890.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N"},{"type":"Ubuntu","score":"medium"}]}