<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:pypa:virtualenv:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3apypavirtualenv/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 01 Oct 2026 04:20:43 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3apypavirtualenv/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Lack of Integrity Verification in virtualenv Seed Wheel Downloads</title><link>https://feed.craftedsignal.io/briefs/2026-10-virtualenv-integrity/</link><pubDate>Thu, 01 Oct 2026 04:20:43 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-virtualenv-integrity/</guid><description>The virtualenv library lacks integrity checks for downloaded pip and setuptools seed wheels, enabling potential arbitrary code execution via compromised mirrors or MITM attacks.</description><content:encoded><![CDATA[<p>The Python library virtualenv (versions up to 21.7.11) contains a critical security flaw where seed wheels, specifically pip and setuptools, are not verified for integrity when downloaded via the --download flag or the automatic periodic-update mechanism. While embedded wheels are protected by a hardcoded SHA256, wheels fetched dynamically over the network are trusted implicitly. This vulnerability, tracked as CVE-2026-102930, allows a malicious actor - such as an entity controlling a compromised PyPI mirror, a rogue index server, or an attacker performing a Man-in-the-Middle (MITM) interception - to substitute a legitimate wheel with a malicious one. If successful, virtualenv will cache the compromised wheel and inject it into every future virtual environment created on the affected host, resulting in persistent arbitrary code execution within those environments.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation results in arbitrary code execution within any virtual environment created using the compromised virtualenv instance. Because the malicious wheel is cached, the persistence of the compromise is high, affecting all subsequent project setups on the host. This vulnerability is particularly concerning in automated build environments, CI/CD pipelines, and developer workstations that frequently create new virtual environments for Python dependency management.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritized actions for security and engineering teams:</p>
<ul>
<li>Update the virtualenv package to a version containing the fix for CVE-2026-102930 (ensure usage is beyond v21.7.11).</li>
<li>Audit existing virtualenv installations for suspicious wheel caches located in standard cache directories.</li>
<li>Implement strict transport security and trusted index configurations for internal Python development pipelines to minimize MITM risks.</li>
<li>Verify if environments are using private indices, as the security check is currently bypassed when custom indexes (PIP_INDEX_URL, PIP_EXTRA_INDEX_URL) are configured.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>supply-chain</category><category>vulnerability</category><category>python</category><category>command-injection</category><category>windows</category></item></channel></rss>