PyPI Released Advisory to Prevent ZIP Parser Confusion Attacks on Python Package Installers
ID: fee33fdd-ddf9-5c68-923f-5d58b7ae663c
STIX ID: report--fee33fdd-ddf9-5c68-923f-5d58b7ae663c
Feed Name: cybersecurityNews.com
Threat Score
This report details a ZIP-format ambiguity in Python wheel distributions where discrepancies between local file headers, the central directory, and the RECORD metadata can let attackers hide payloads that installers may extract; PyPI will enforce stricter archive validation and block mismatched wheels beginning February 1, 2026, and no confirmed real-world exploitation has been reported to date.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
