FlawAtlas
Search the atlas
CVE-2021-3572 High

Improper Input Validation in pip

A flaw was found in python-pip in the way it handled Unicode separators in git references. A remote attacker could possibly use this issue to install a different revision on a repository. The highest threat from this vulnerability is to data integrity. This is fixed in python-pip version 21.1.

Exploit probability 1.7%
Published November 15, 2021
Required by Not available
Last source change March 24, 2026

02 / AFFECTED SOFTWARE

Affected packages

Unknown Unknown

23 explicit affected versions

PyPI pip

102 explicit affected versions

PyPI pip

102 explicit affected versions

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities PYSEC-2021-437

A flaw was found in python-pip in the way it handled Unicode separators in git references. A remote attacker could possibly use this issue to install a different revision on a repository. The highest threat from this vulnerability is to data integrity. This is fixed in python-pip version 21.1.

View original source
Open Source Vulnerabilities GHSA-5xp3-jfq3-5q8x

A flaw was found in python-pip in the way it handled Unicode separators in git references. A remote attacker could possibly use this issue to install a different revision on a repository. The highest threat from this vulnerability is to data integrity. This is fixed in python-pip version 21.1.

View original source
Open Source Vulnerabilities CVE-2021-3572

A flaw was found in python-pip in the way it handled Unicode separators in git references. A remote attacker could possibly use this issue to install a different revision on a repository. The highest threat from this vulnerability is to data integrity. This is fixed in python-pip version 21.1.

View original source

05 / REFERENCES

Further evidence