CVE-2021-3572
Description
A flaw was found in python-pip in the way it handled Unicode separators in git references. A remote attacker could possibly use this issue to install a different revision on a repository. The highest threat from this vulnerability is to data integrity. This is fixed in python-pip version 21.1.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A flaw in python-pip's handling of Unicode separators in git references could allow a remote attacker to install a different repository revision, compromising data integrity.
Vulnerability
A flaw exists in python-pip's VCS support when parsing git references. The code used Unicode whitespace characters as separators when splitting git references, but git allows such characters in tag names. This allowed a maliciously crafted tag to hijack a commit-based pin, causing pip to resolve to a different revision than intended. The vulnerability affects all versions of pip before 21.1. [2][4]
Exploitation
An attacker needs write access to a repository (or the ability to create tags) and the victim must use a commit-based pin (e.g., git+https://...@). The attacker creates a tag containing Unicode whitespace characters that, when split by pip, causes the reference to resolve to a different revision. No user interaction beyond the normal pip install command is required. [4]
Impact
Successful exploitation leads to installation of a different revision of the repository than the one intended by the user. This compromises data integrity, as the attacker could inject malicious code or dependencies into the installed package. The highest threat is to data integrity, with potential for further compromise depending on the injected content. [2][4]
Mitigation
The vulnerability is fixed in python-pip version 21.1, released in April 2021. Users should upgrade to pip 21.1 or later. Red Hat provided updates via RHSA-2021:3254 for the rh-python38 collection. No workarounds are available; upgrading is the only mitigation. [1][2][4]
AI Insight generated on May 21, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
pipPyPI | < 21.1 | 21.1 |
Affected products
182- python-pip/python-pipdescription
- osv-coords181 versionspkg:apk/chainguard/pypy-bootstrappkg:pypi/pippkg:rpm/almalinux/python38-asn1cryptopkg:rpm/almalinux/python38-atomicwritespkg:rpm/almalinux/python38-attrspkg:rpm/almalinux/python38-babelpkg:rpm/almalinux/python38-cffipkg:rpm/almalinux/python38-chardetpkg:rpm/almalinux/python38-cryptographypkg:rpm/almalinux/python38-Cythonpkg:rpm/almalinux/python38-idnapkg:rpm/almalinux/python38-jinja2pkg:rpm/almalinux/python38-markupsafepkg:rpm/almalinux/python38-mod_wsgipkg:rpm/almalinux/python38-more-itertoolspkg:rpm/almalinux/python38-numpypkg:rpm/almalinux/python38-numpy-docpkg:rpm/almalinux/python38-numpy-f2pypkg:rpm/almalinux/python38-packagingpkg:rpm/almalinux/python38-pluggypkg:rpm/almalinux/python38-plypkg:rpm/almalinux/python38-psutilpkg:rpm/almalinux/python38-psycopg2pkg:rpm/almalinux/python38-psycopg2-docpkg:rpm/almalinux/python38-psycopg2-testspkg:rpm/almalinux/python38-pypkg:rpm/almalinux/python38-pycparserpkg:rpm/almalinux/python38-PyMySQLpkg:rpm/almalinux/python38-pyparsingpkg:rpm/almalinux/python38-pysockspkg:rpm/almalinux/python38-pytestpkg:rpm/almalinux/python38-pytzpkg:rpm/almalinux/python38-pyyamlpkg:rpm/almalinux/python38-requestspkg:rpm/almalinux/python38-scipypkg:rpm/almalinux/python38-setuptoolspkg:rpm/almalinux/python38-setuptools-wheelpkg:rpm/almalinux/python38-sixpkg:rpm/almalinux/python38-urllib3pkg:rpm/almalinux/python38-wcwidthpkg:rpm/almalinux/python38-wheelpkg:rpm/almalinux/python38-wheel-wheelpkg:rpm/almalinux/python39-attrspkg:rpm/almalinux/python39-cffipkg:rpm/almalinux/python39-chardetpkg:rpm/almalinux/python39-cryptographypkg:rpm/almalinux/python39-Cythonpkg:rpm/almalinux/python39-idnapkg:rpm/almalinux/python39-iniconfigpkg:rpm/almalinux/python39-mod_wsgipkg:rpm/almalinux/python39-more-itertoolspkg:rpm/almalinux/python39-numpypkg:rpm/almalinux/python39-numpy-docpkg:rpm/almalinux/python39-numpy-f2pypkg:rpm/almalinux/python39-packagingpkg:rpm/almalinux/python39-pluggypkg:rpm/almalinux/python39-plypkg:rpm/almalinux/python39-psutilpkg:rpm/almalinux/python39-psycopg2pkg:rpm/almalinux/python39-psycopg2-docpkg:rpm/almalinux/python39-psycopg2-testspkg:rpm/almalinux/python39-pypkg:rpm/almalinux/python39-pycparserpkg:rpm/almalinux/python39-PyMySQLpkg:rpm/almalinux/python39-pyparsingpkg:rpm/almalinux/python39-pysockspkg:rpm/almalinux/python39-pytestpkg:rpm/almalinux/python39-pyyamlpkg:rpm/almalinux/python39-requestspkg:rpm/almalinux/python39-scipypkg:rpm/almalinux/python39-setuptoolspkg:rpm/almalinux/python39-setuptools-wheelpkg:rpm/almalinux/python39-sixpkg:rpm/almalinux/python39-tomlpkg:rpm/almalinux/python39-urllib3pkg:rpm/almalinux/python39-wcwidthpkg:rpm/almalinux/python39-wheelpkg:rpm/almalinux/python39-wheel-wheelpkg:rpm/almalinux/python3-pippkg:rpm/opensuse/python36&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/python39-core&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/python39-core&distro=openSUSE%20Leap%2015.4pkg:rpm/opensuse/python39&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/python39&distro=openSUSE%20Leap%2015.4pkg:rpm/opensuse/python39&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/python39-documentation&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/python39-documentation&distro=openSUSE%20Leap%2015.4pkg:rpm/opensuse/python39-pip&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/python3-core&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/python3&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/python3-documentation&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/python-base&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/python&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/python&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/python-doc&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/python-pip&distro=openSUSE%20Leap%2015.2pkg:rpm/opensuse/python-pip&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/python-pip-wheel&distro=openSUSE%20Leap%2015.2pkg:rpm/opensuse/python-pip-wheel&distro=openSUSE%20Leap%2015.3pkg:rpm/suse/python36-core&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5pkg:rpm/suse/python36-core&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP5pkg:rpm/suse/python36-core&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP5pkg:rpm/suse/python36&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5pkg:rpm/suse/python36&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP5pkg:rpm/suse/python36-pip&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5pkg:rpm/suse/python36-pip&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP5pkg:rpm/suse/python39-core&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP3pkg:rpm/suse/python39-core&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Development%20Tools%2015%20SP3pkg:rpm/suse/python39&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP3pkg:rpm/suse/python39-pip&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP3pkg:rpm/suse/python3-base&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Web%20and%20Scripting%2012pkg:rpm/suse/python3-base&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5pkg:rpm/suse/python3-base&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP5pkg:rpm/suse/python3-base&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP5pkg:rpm/suse/python3-core&distro=SUSE%20Enterprise%20Storage%206pkg:rpm/suse/python3-core&distro=SUSE%20Enterprise%20Storage%207pkg:rpm/suse/python3-core&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP1-ESPOSpkg:rpm/suse/python3-core&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP1-LTSSpkg:rpm/suse/python3-core&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP2-ESPOSpkg:rpm/suse/python3-core&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP2-LTSSpkg:rpm/suse/python3-core&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-ESPOSpkg:rpm/suse/python3-core&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-LTSSpkg:rpm/suse/python3-core&distro=SUSE%20Linux%20Enterprise%20Micro%205.1pkg:rpm/suse/python3-core&distro=SUSE%20Linux%20Enterprise%20Micro%205.2pkg:rpm/suse/python3-core&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP3pkg:rpm/suse/python3-core&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Development%20Tools%2015%20SP3pkg:rpm/suse/python3-core&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP1-BCLpkg:rpm/suse/python3-core&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP1-LTSSpkg:rpm/suse/python3-core&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP2-BCLpkg:rpm/suse/python3-core&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP2-LTSSpkg:rpm/suse/python3-core&distro=SUSE%20Linux%20Enterprise%20Server%2015-LTSSpkg:rpm/suse/python3-core&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015pkg:rpm/suse/python3-core&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP1pkg:rpm/suse/python3-core&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP2pkg:rpm/suse/python3-core&distro=SUSE%20Manager%20Proxy%204.1pkg:rpm/suse/python3-core&distro=SUSE%20Manager%20Retail%20Branch%20Server%204.1pkg:rpm/suse/python3-core&distro=SUSE%20Manager%20Server%204.1pkg:rpm/suse/python3&distro=SUSE%20Enterprise%20Storage%206pkg:rpm/suse/python3&distro=SUSE%20Enterprise%20Storage%207pkg:rpm/suse/python3&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP1-ESPOSpkg:rpm/suse/python3&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP1-LTSSpkg:rpm/suse/python3&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP2-ESPOSpkg:rpm/suse/python3&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP2-LTSSpkg:rpm/suse/python3&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-ESPOSpkg:rpm/suse/python3&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-LTSSpkg:rpm/suse/python3&distro=SUSE%20Linux%20Enterprise%20Micro%205.1pkg:rpm/suse/python3&distro=SUSE%20Linux%20Enterprise%20Micro%205.2pkg:rpm/suse/python3&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP3pkg:rpm/suse/python3&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Web%20and%20Scripting%2012pkg:rpm/suse/python3&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5pkg:rpm/suse/python3&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP1-BCLpkg:rpm/suse/python3&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP1-LTSSpkg:rpm/suse/python3&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP2-BCLpkg:rpm/suse/python3&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP2-LTSSpkg:rpm/suse/python3&distro=SUSE%20Linux%20Enterprise%20Server%2015-LTSSpkg:rpm/suse/python3&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP5pkg:rpm/suse/python3&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015pkg:rpm/suse/python3&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP1pkg:rpm/suse/python3&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP2pkg:rpm/suse/python3&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP5pkg:rpm/suse/python3&distro=SUSE%20Manager%20Proxy%204.1pkg:rpm/suse/python3&distro=SUSE%20Manager%20Retail%20Branch%20Server%204.1pkg:rpm/suse/python3&distro=SUSE%20Manager%20Server%204.1pkg:rpm/suse/python-base&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP3pkg:rpm/suse/python-base&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Python%202%2015%20SP3pkg:rpm/suse/python-base&distro=SUSE%20Linux%20Enterprise%20Real%20Time%2015%20SP2pkg:rpm/suse/python&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP3pkg:rpm/suse/python&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Desktop%20Applications%2015%20SP3pkg:rpm/suse/python&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Python%202%2015%20SP3pkg:rpm/suse/python&distro=SUSE%20Linux%20Enterprise%20Real%20Time%2015%20SP2pkg:rpm/suse/python-pip&distro=HPE%20Helion%20OpenStack%208pkg:rpm/suse/python-pip&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP2pkg:rpm/suse/python-pip&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP3pkg:rpm/suse/python-pip&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Public%20Cloud%2012pkg:rpm/suse/python-pip&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Python%202%2015%20SP2pkg:rpm/suse/python-pip&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Python%202%2015%20SP3pkg:rpm/suse/python-pip&distro=SUSE%20OpenStack%20Cloud%208pkg:rpm/suse/python-pip&distro=SUSE%20OpenStack%20Cloud%209pkg:rpm/suse/python-pip&distro=SUSE%20OpenStack%20Cloud%20Crowbar%208pkg:rpm/suse/python-pip&distro=SUSE%20OpenStack%20Cloud%20Crowbar%209pkg:rpm/suse/python-pip-wheel&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP3
< 7.3.18-r1+ 180 more
- (no CPE)range: < 7.3.18-r1
- (no CPE)range: < 21.1
- (no CPE)range: < 1.2.0-3.module_el8.6.0+2778+cd494b30
- (no CPE)range: < 1.3.0-8.module_el8.6.0+2778+cd494b30
- (no CPE)range: < 19.3.0-3.module_el8.6.0+2778+cd494b30
- (no CPE)range: < 2.7.0-11.module_el8.6.0+2778+cd494b30
- (no CPE)range: < 1.13.2-3.module_el8.6.0+2778+cd494b30
- (no CPE)range: < 3.0.4-19.module_el8.6.0+2778+cd494b30
- (no CPE)range: < 2.8-3.module_el8.6.0+2778+cd494b30
- (no CPE)range: < 0.29.14-4.module_el8.6.0+2778+cd494b30
- (no CPE)range: < 2.8-6.module_el8.6.0+2778+cd494b30
- (no CPE)range: < 2.10.3-5.module_el8.6.0+2778+cd494b30
- (no CPE)range: < 1.1.1-6.module_el8.6.0+2778+cd494b30
- (no CPE)range: < 4.6.8-3.module_el8.6.0+2778+cd494b30
- (no CPE)range: < 7.2.0-5.module_el8.6.0+2778+cd494b30
- (no CPE)range: < 1.17.3-6.module_el8.6.0+2778+cd494b30
- (no CPE)range: < 1.17.3-6.module_el8.6.0+2778+cd494b30
- (no CPE)range: < 1.17.3-6.module_el8.6.0+2778+cd494b30
- (no CPE)range: < 19.2-3.module_el8.6.0+2778+cd494b30
- (no CPE)range: < 0.13.0-3.module_el8.6.0+2778+cd494b30
- (no CPE)range: < 3.11-10.module_el8.6.0+2778+cd494b30
- (no CPE)range: < 5.6.4-4.module_el8.6.0+2778+cd494b30
- (no CPE)range: < 2.8.4-4.module_el8.6.0+2778+cd494b30
- (no CPE)range: < 2.8.4-4.module_el8.6.0+2778+cd494b30
- (no CPE)range: < 2.8.4-4.module_el8.6.0+2778+cd494b30
- (no CPE)range: < 1.8.0-8.module_el8.6.0+2778+cd494b30
- (no CPE)range: < 2.19-3.module_el8.6.0+2778+cd494b30
- (no CPE)range: < 0.10.1-1.module_el8.6.0+2778+cd494b30
- (no CPE)range: < 2.4.5-3.module_el8.6.0+2778+cd494b30
- (no CPE)range: < 1.7.1-4.module_el8.6.0+2778+cd494b30
- (no CPE)range: < 4.6.6-3.module_el8.6.0+2778+cd494b30
- (no CPE)range: < 2019.3-3.module_el8.6.0+2778+cd494b30
- (no CPE)range: < 5.4.1-1.module_el8.6.0+2778+cd494b30
- (no CPE)range: < 2.22.0-9.module_el8.6.0+2778+cd494b30
- (no CPE)range: < 1.3.1-4.module_el8.6.0+2778+cd494b30
- (no CPE)range: < 41.6.0-5.module_el8.6.0+2778+cd494b30
- (no CPE)range: < 41.6.0-5.module_el8.6.0+2778+cd494b30
- (no CPE)range: < 1.12.0-10.module_el8.6.0+2778+cd494b30
- (no CPE)range: < 1.25.7-5.module_el8.6.0+2778+cd494b30
- (no CPE)range: < 0.1.7-16.module_el8.6.0+2778+cd494b30
- (no CPE)range: < 0.33.6-6.module_el8.6.0+2778+cd494b30
- (no CPE)range: < 0.33.6-6.module_el8.6.0+2778+cd494b30
- (no CPE)range: < 20.3.0-2.module_el8.6.0+2780+a40f65e1
- (no CPE)range: < 1.14.3-2.module_el8.6.0+2780+a40f65e1
- (no CPE)range: < 3.0.4-19.module_el8.6.0+2780+a40f65e1
- (no CPE)range: < 3.3.1-2.module_el8.6.0+2780+a40f65e1
- (no CPE)range: < 0.29.21-5.module_el8.6.0+2780+a40f65e1
- (no CPE)range: < 2.10-3.module_el8.6.0+2780+a40f65e1
- (no CPE)range: < 1.1.1-2.module_el8.6.0+2780+a40f65e1
- (no CPE)range: < 4.7.1-4.module_el8.6.0+2780+a40f65e1
- (no CPE)range: < 8.5.0-2.module_el8.6.0+2780+a40f65e1
- (no CPE)range: < 1.19.4-3.module_el8.6.0+2780+a40f65e1
- (no CPE)range: < 1.19.4-3.module_el8.6.0+2780+a40f65e1
- (no CPE)range: < 1.19.4-3.module_el8.6.0+2780+a40f65e1
- (no CPE)range: < 20.4-4.module_el8.6.0+2780+a40f65e1
- (no CPE)range: < 0.13.1-3.module_el8.6.0+2780+a40f65e1
- (no CPE)range: < 3.11-10.module_el8.6.0+2780+a40f65e1
- (no CPE)range: < 5.8.0-4.module_el8.6.0+2780+a40f65e1
- (no CPE)range: < 2.8.6-2.module_el8.6.0+2780+a40f65e1
- (no CPE)range: < 2.8.6-2.module_el8.6.0+2780+a40f65e1
- (no CPE)range: < 2.8.6-2.module_el8.6.0+2780+a40f65e1
- (no CPE)range: < 1.10.0-1.module_el8.6.0+2780+a40f65e1
- (no CPE)range: < 2.20-3.module_el8.6.0+2780+a40f65e1
- (no CPE)range: < 0.10.1-2.module_el8.6.0+2780+a40f65e1
- (no CPE)range: < 2.4.7-5.module_el8.6.0+2780+a40f65e1
- (no CPE)range: < 1.7.1-4.module_el8.6.0+2780+a40f65e1
- (no CPE)range: < 6.0.2-2.module_el8.6.0+2780+a40f65e1
- (no CPE)range: < 5.4.1-1.module_el8.6.0+2780+a40f65e1
- (no CPE)range: < 2.25.0-2.module_el8.6.0+2780+a40f65e1
- (no CPE)range: < 1.5.4-3.module_el8.6.0+2780+a40f65e1
- (no CPE)range: < 50.3.2-4.module_el8.6.0+2780+a40f65e1
- (no CPE)range: < 50.3.2-4.module_el8.6.0+2780+a40f65e1
- (no CPE)range: < 1.15.0-3.module_el8.6.0+2780+a40f65e1
- (no CPE)range: < 0.10.1-5.module_el8.6.0+2780+a40f65e1
- (no CPE)range: < 1.25.10-4.module_el8.6.0+2780+a40f65e1
- (no CPE)range: < 0.2.5-3.module_el8.6.0+2780+a40f65e1
- (no CPE)range: < 1:0.35.1-4.module_el8.6.0+2780+a40f65e1
- (no CPE)range: < 1:0.35.1-4.module_el8.6.0+2780+a40f65e1
- (no CPE)range: < 9.0.3-20.el8
- (no CPE)range: < 3.6.15-10.1
- (no CPE)range: < 3.9.10-150300.4.8.1
- (no CPE)range: < 3.9.10-150300.4.8.1
- (no CPE)range: < 3.9.10-150300.4.8.2
- (no CPE)range: < 3.9.10-150300.4.8.2
- (no CPE)range: < 3.9.13-2.1
- (no CPE)range: < 3.9.10-150300.4.8.1
- (no CPE)range: < 3.9.10-150300.4.8.1
- (no CPE)range: < 20.2.4-7.8.1
- (no CPE)range: < 3.6.15-150300.10.21.1
- (no CPE)range: < 3.6.15-150300.10.21.1
- (no CPE)range: < 3.6.15-150300.10.21.1
- (no CPE)range: < 2.7.18-150000.38.2
- (no CPE)range: < 2.7.18-150000.38.1
- (no CPE)range: < 2.7.18-18.1
- (no CPE)range: < 2.7.18-150000.38.1
- (no CPE)range: < 10.0.1-lp152.4.9.1
- (no CPE)range: < 20.0.2-6.15.1
- (no CPE)range: < 10.0.1-lp152.4.9.1
- (no CPE)range: < 10.0.1-3.9.1
- (no CPE)range: < 3.6.15-21.4
- (no CPE)range: < 3.6.15-21.4
- (no CPE)range: < 3.6.15-21.4
- (no CPE)range: < 3.6.15-21.5
- (no CPE)range: < 3.6.15-21.5
- (no CPE)range: < 20.2.4-8.9.1
- (no CPE)range: < 20.2.4-8.9.1
- (no CPE)range: < 3.9.10-150300.4.8.1
- (no CPE)range: < 3.9.10-150300.4.8.1
- (no CPE)range: < 3.9.10-150300.4.8.2
- (no CPE)range: < 20.2.4-7.8.1
- (no CPE)range: < 3.4.10-25.88.1
- (no CPE)range: < 3.4.10-25.88.1
- (no CPE)range: < 3.4.10-25.88.1
- (no CPE)range: < 3.4.10-25.88.1
- (no CPE)range: < 3.6.15-150000.3.106.1
- (no CPE)range: < 3.6.15-150000.3.106.1
- (no CPE)range: < 3.6.15-150000.3.106.1
- (no CPE)range: < 3.6.15-150000.3.106.1
- (no CPE)range: < 3.6.15-150000.3.106.1
- (no CPE)range: < 3.6.15-150000.3.106.1
- (no CPE)range: < 3.6.15-150000.3.106.1
- (no CPE)range: < 3.6.15-150000.3.106.1
- (no CPE)range: < 3.6.15-150000.3.106.1
- (no CPE)range: < 3.6.15-150300.10.21.1
- (no CPE)range: < 3.6.15-150300.10.21.1
- (no CPE)range: < 3.6.15-150300.10.21.1
- (no CPE)range: < 3.6.15-150000.3.106.1
- (no CPE)range: < 3.6.15-150000.3.106.1
- (no CPE)range: < 3.6.15-150000.3.106.1
- (no CPE)range: < 3.6.15-150000.3.106.1
- (no CPE)range: < 3.6.15-150000.3.106.1
- (no CPE)range: < 3.6.15-150000.3.106.1
- (no CPE)range: < 3.6.15-150000.3.106.1
- (no CPE)range: < 3.6.15-150000.3.106.1
- (no CPE)range: < 3.6.15-150000.3.106.1
- (no CPE)range: < 3.6.15-150000.3.106.1
- (no CPE)range: < 3.6.15-150000.3.106.1
- (no CPE)range: < 3.6.15-150000.3.106.1
- (no CPE)range: < 3.6.15-150000.3.106.1
- (no CPE)range: < 3.6.15-150000.3.106.1
- (no CPE)range: < 3.6.15-150000.3.106.1
- (no CPE)range: < 3.6.15-150000.3.106.1
- (no CPE)range: < 3.6.15-150000.3.106.1
- (no CPE)range: < 3.6.15-150000.3.106.1
- (no CPE)range: < 3.6.15-150000.3.106.1
- (no CPE)range: < 3.6.15-150000.3.106.1
- (no CPE)range: < 3.6.15-150300.10.21.1
- (no CPE)range: < 3.6.15-150300.10.21.1
- (no CPE)range: < 3.4.10-25.88.1
- (no CPE)range: < 3.4.10-25.88.1
- (no CPE)range: < 3.6.15-150000.3.106.1
- (no CPE)range: < 3.6.15-150000.3.106.1
- (no CPE)range: < 3.6.15-150000.3.106.1
- (no CPE)range: < 3.6.15-150000.3.106.1
- (no CPE)range: < 3.6.15-150000.3.106.1
- (no CPE)range: < 3.4.10-25.88.1
- (no CPE)range: < 3.6.15-150000.3.106.1
- (no CPE)range: < 3.6.15-150000.3.106.1
- (no CPE)range: < 3.6.15-150000.3.106.1
- (no CPE)range: < 3.4.10-25.88.1
- (no CPE)range: < 3.6.15-150000.3.106.1
- (no CPE)range: < 3.6.15-150000.3.106.1
- (no CPE)range: < 3.6.15-150000.3.106.1
- (no CPE)range: < 2.7.18-150000.38.2
- (no CPE)range: < 2.7.18-150000.38.2
- (no CPE)range: < 2.7.18-150000.38.2
- (no CPE)range: < 2.7.18-150000.38.1
- (no CPE)range: < 2.7.18-150000.38.1
- (no CPE)range: < 2.7.18-150000.38.1
- (no CPE)range: < 2.7.18-150000.38.1
- (no CPE)range: < 9.0.1-3.6.1
- (no CPE)range: < 20.0.2-6.15.1
- (no CPE)range: < 20.0.2-6.15.1
- (no CPE)range: < 10.0.1-13.6.1
- (no CPE)range: < 20.0.2-6.15.1
- (no CPE)range: < 20.0.2-6.15.1
- (no CPE)range: < 9.0.1-3.6.1
- (no CPE)range: < 9.0.1-4.6.1
- (no CPE)range: < 9.0.1-3.6.1
- (no CPE)range: < 9.0.1-4.6.1
- (no CPE)range: < 10.0.1-3.9.1
Patches
1e46bdda97113Merge pull request #9827 from pradyunsg/fix-git-improper-tag-handling
2 files changed · +11 −2
news/9827.bugfix.rst+3 −0 added@@ -0,0 +1,3 @@ +**SECURITY**: Stop splitting on unicode separators in git references, +which could be maliciously used to install a different revision on the +repository.
src/pip/_internal/vcs/git.py+8 −2 modified@@ -131,9 +131,15 @@ def get_revision_sha(cls, dest, rev): on_returncode='ignore', ) refs = {} - for line in output.strip().splitlines(): + # NOTE: We do not use splitlines here since that would split on other + # unicode separators, which can be maliciously used to install a + # different revision. + for line in output.strip().split("\n"): + line = line.rstrip("\r") + if not line: + continue try: - ref_sha, ref_name = line.split() + ref_sha, ref_name = line.split(" ", maxsplit=2) except ValueError: # Include the offending line to simplify troubleshooting if # this error ever occurs.
Vulnerability mechanics
Generated on May 9, 2026. Inputs: CWE entries + fix-commit diffs from this CVE's patches. Citations validated against bundle.
References
12- github.com/advisories/GHSA-5xp3-jfq3-5q8xghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2021-3572ghsaADVISORY
- access.redhat.com/errata/RHSA-2021:3254ghsaWEB
- bugzilla.redhat.com/show_bug.cgighsaWEB
- github.com/pypa/advisory-database/tree/main/vulns/pip/PYSEC-2021-437.yamlghsaWEB
- github.com/pypa/pip/commit/e46bdda9711392fec0c45c1175bae6db847cb30bghsaWEB
- github.com/pypa/pip/pull/9827ghsaWEB
- packetstormsecurity.com/files/162712/USN-4961-1.txtghsaWEB
- security.netapp.com/advisory/ntap-20240621-0006ghsaWEB
- www.oracle.com/security-alerts/cpuapr2022.htmlghsaWEB
- www.oracle.com/security-alerts/cpujul2022.htmlghsaWEB
- security.netapp.com/advisory/ntap-20240621-0006/mitre
News mentions
0No linked articles in our index yet.