VYPR

apk package

wolfi/py3.12-setuptools

pkg:apk/wolfi/py3.12-setuptools

Vulnerabilities (3)

  • CVE-2026-59890MedJul 8, 2026
    affected < 83.0.0-r0fixed 83.0.0-r0

    setuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. Prior to 83.0.0, FileList applied MANIFEST.in exclude, global-exclude, recursive-exclude, and prune directives by matching compiled glob patterns against on-disk file na

  • CVE-2026-24049HigJan 22, 2026
    affected < 80.10.2-r0fixed 80.10.2-r0

    wheel is a command line tool for manipulating Python wheel files, as defined in PEP 427. In versions 0.40.0 through 0.46.1, the unpack function is vulnerable to file permission modification through mishandling of file permissions after extraction. The logic blindly trusts the fil

  • CVE-2026-23949HigJan 20, 2026
    affected < 80.10.1-r0fixed 80.10.1-r0

    jaraco.context, an open-source software package that provides some useful decorators and context managers, has a Zip Slip path traversal vulnerability in the `jaraco.context.tarball()` function starting in version 5.2.0 and prior to version 6.1.0. The vulnerability may allow atta