Skip to content
Threat Feed
high advisory

Lack of Integrity Verification in virtualenv Seed Wheel Downloads

The virtualenv library lacks integrity checks for downloaded pip and setuptools seed wheels, enabling potential arbitrary code execution via compromised mirrors or MITM attacks.

CVE search metadata

CVE search record: CVE-2026-102930. KEV: no. Product: virtualenv (<= 21.7.11), virtualenv (<= 21.7.12). Brief: Lack of Integrity Verification in virtualenv Seed Wheel Downloads. Brief link: https://feed.craftedsignal.io/briefs/2026-10-virtualenv-integrity/

What's new

  • 1. added coverage for virtualenv (<= 21.7.11) Oct 2, 02:19 via ghsa
  • 2. added coverage for virtualenv (<= 21.7.12) Oct 1, 20:22 via ghsa

The Python library virtualenv (versions up to 21.7.11) contains a critical security flaw where seed wheels, specifically pip and setuptools, are not verified for integrity when downloaded via the --download flag or the automatic periodic-update mechanism. While embedded wheels are protected by a hardcoded SHA256, wheels fetched dynamically over the network are trusted implicitly. This vulnerability, tracked as CVE-2026-102930, allows a malicious actor - such as an entity controlling a compromised PyPI mirror, a rogue index server, or an attacker performing a Man-in-the-Middle (MITM) interception - to substitute a legitimate wheel with a malicious one. If successful, virtualenv will cache the compromised wheel and inject it into every future virtual environment created on the affected host, resulting in persistent arbitrary code execution within those environments.

Impact

Successful exploitation results in arbitrary code execution within any virtual environment created using the compromised virtualenv instance. Because the malicious wheel is cached, the persistence of the compromise is high, affecting all subsequent project setups on the host. This vulnerability is particularly concerning in automated build environments, CI/CD pipelines, and developer workstations that frequently create new virtual environments for Python dependency management.

Recommendation

Prioritized actions for security and engineering teams:

  • Update the virtualenv package to a version containing the fix for CVE-2026-102930 (ensure usage is beyond v21.7.11).
  • Audit existing virtualenv installations for suspicious wheel caches located in standard cache directories.
  • Implement strict transport security and trusted index configurations for internal Python development pipelines to minimize MITM risks.
  • Verify if environments are using private indices, as the security check is currently bypassed when custom indexes (PIP_INDEX_URL, PIP_EXTRA_INDEX_URL) are configured.

Immediate actions

Upgrade virtualenv to 21.7.12 or later

IT Operations 48h

Mitigations

Upgrade virtualenv to version > 21.7.11.

immediate IT Operations

CVE-2026-102930