logo

PyPI Released Advisory to Prevent ZIP Parser Confusion Attacks on Python Package Installers

ID: fee33fdd-ddf9-5c68-923f-5d58b7ae663c

STIX ID: report--fee33fdd-ddf9-5c68-923f-5d58b7ae663c

Feed Name: cybersecurityNews.com

Threat Score
60/100

Date Published: 2025-08-08

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

This report details a ZIP-format ambiguity in Python wheel distributions where discrepancies between local file headers, the central directory, and the RECORD metadata can let attackers hide payloads that installers may extract; PyPI will enforce stricter archive validation and block mismatched wheels beginning February 1, 2026, and no confirmed real-world exploitation has been reported to date.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.