Intel

AIKIDO-2026-46060

virtualenv is vulnerable to Download of Code Without Integrity Check

Download of Code Without Integrity CheckGHSA-94p9-xgh2-xp45 Published 5 days ago

37

Low Risk

This Affects:

PYTHONvirtualenv
0.0.1 - 21.7.11
Fixed in 21.7.12
Are you affected? Scan for Free

TL;DR

virtualenv's download_wheel() runs pip download for the periodic seed-wheel update and the --download flag and hands the returned wheel straight to the seeder without checking its bytes. A compromised index, a stale mirror, or an intercepted download can substitute a different wheel under the same distribution, version, and filename, and virtualenv caches and seeds that wheel into every environment created afterward with no warning. The fix computes the downloaded wheel's sha256 and compares it against the digest PyPI's public JSON API reports for that release, skipping the check only when a custom index is configured.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and you rely on virtualenv's periodic seed-wheel update or the --download flag against a package index that could be compromised, stale, or subject to an intercepted (MITM'd) connection.

Background info

virtualenv is vulnerable to Download of Code Without Integrity Check in versions 0.0.1 - 21.7.11.

How to fix this

Upgrade the virtualenv library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform