{
  "document": {
    "aggregate_severity": {
      "text": "Medium"
    },
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "distribution": {
      "text": "TuxCare License Agreement",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Cloud Linux Inc. and provide a link to the original.",
        "title": "Terms of Use"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://tuxcare.com/contact/",
      "name": "TuxCare",
      "namespace": "https://tuxcare.com/"
    },
    "references": [
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.tuxcare.com/csaf/v2/els_os/oraclelinux7els/vex/2026/cve-2026-13346-els_os-oraclelinux7els.json"
      }
    ],
    "tracking": {
      "current_release_date": "2026-08-21T19:12:26Z",
      "generator": {
        "date": "2026-08-21T19:12:26Z",
        "engine": {
          "name": "pyCSAF"
        }
      },
      "id": "CVE-2026-13346-ELS_OS-ORACLELINUX7ELS",
      "initial_release_date": "2026-07-29T19:16:00Z",
      "revision_history": [
        {
          "date": "2026-07-29T19:16:00Z",
          "number": "1",
          "summary": "Initial version"
        },
        {
          "date": "2026-08-21T12:44:39Z",
          "number": "2",
          "summary": "Official Publication"
        },
        {
          "date": "2026-08-21T19:12:26Z",
          "number": "3",
          "summary": "Update document"
        }
      ],
      "status": "final",
      "version": "3"
    },
    "title": "Security update on CVE-2026-13346"
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Oracle Linux 7",
                "product": {
                  "name": "Oracle Linux 7",
                  "product_id": "Oracle-Linux-7",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:o:oracle:linux:7:*:*:*:*:*:*:*"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Oracle Linux"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "python3-pip-0:9.0.3-8.0.3.el7.noarch",
                "product": {
                  "name": "python3-pip-0:9.0.3-8.0.3.el7.noarch",
                  "product_id": "python3-pip-0:9.0.3-8.0.3.el7.noarch",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/oracle/python3-pip@9.0.3-8.0.3.el7?arch=noarch"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "noarch"
          }
        ],
        "category": "vendor",
        "name": "Oracle Corporation"
      },
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version",
                "name": "python3-pip-0:9.0.3-8.0.3.el7.tuxcare.els1.noarch",
                "product": {
                  "name": "python3-pip-0:9.0.3-8.0.3.el7.tuxcare.els1.noarch",
                  "product_id": "python3-pip-0:9.0.3-8.0.3.el7.tuxcare.els1.noarch",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/python3-pip@9.0.3-8.0.3.el7.tuxcare.els1?arch=noarch"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "noarch"
          }
        ],
        "category": "vendor",
        "name": "TuxCare"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "python3-pip-0:9.0.3-8.0.3.el7.tuxcare.els1.noarch as a component of Oracle Linux 7",
          "product_id": "Oracle-Linux-7:python3-pip-0:9.0.3-8.0.3.el7.tuxcare.els1.noarch"
        },
        "product_reference": "python3-pip-0:9.0.3-8.0.3.el7.tuxcare.els1.noarch",
        "relates_to_product_reference": "Oracle-Linux-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "python3-pip-0:9.0.3-8.0.3.el7.noarch as a component of Oracle Linux 7",
          "product_id": "Oracle-Linux-7:python3-pip-0:9.0.3-8.0.3.el7.noarch"
        },
        "product_reference": "python3-pip-0:9.0.3-8.0.3.el7.noarch",
        "relates_to_product_reference": "Oracle-Linux-7"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2026-13346",
      "cwe": {
        "id": "CWE-36",
        "name": "Absolute Path Traversal"
      },
      "notes": [
        {
          "category": "description",
          "text": "pip would incorrectly handle doubly-encoded package URLs from indexes allowing for files to be installed to arbitrary locations on disk even when installing wheels.\n\n\n\n\nThis vulnerability requires downloading or installing a package from a malicious package index to succeed, malicious packages alone are not able to exploit this vulnerability. Note that this vulnerability only materially impacts users running `pip download` with the `--only-binary` option as installing source distributions from an untrusted index is already an unsafe operation that executes code during install time.",
          "title": "Vulnerability description"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "known_affected": [
          "Oracle-Linux-7:python3-pip-0:9.0.3-8.0.3.el7.noarch",
          "Oracle-Linux-7:python3-pip-0:9.0.3-8.0.3.el7.tuxcare.els1.noarch"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2026-13346"
        },
        {
          "category": "external",
          "summary": "https://github.com/pypa/pip/pull/14110",
          "url": "https://github.com/pypa/pip/pull/14110"
        },
        {
          "category": "external",
          "summary": "https://mail.python.org/archives/list/security-announce@python.org/thread/L2BNQGGVQCEV7DROOORQ7WFKKFF2OOQX/",
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/L2BNQGGVQCEV7DROOORQ7WFKKFF2OOQX/"
        },
        {
          "category": "external",
          "summary": "http://www.openwall.com/lists/oss-security/2026/07/29/7",
          "url": "http://www.openwall.com/lists/oss-security/2026/07/29/7"
        }
      ],
      "release_date": "2026-07-29T19:16:00Z",
      "remediations": [
        {
          "category": "no_fix_planned",
          "date": "2026-08-21T15:32:41.810894Z",
          "details": "Low practical risk: exploitation requires a user to explicitly direct pip to a malicious package index and run pip download with --only-binary, which is not the default workflow and involves deliberate user action. Even if triggered, it only writes files with the invoking user’s permissions during that local operation and does not provide remote code execution. In centrally managed server/VM environments that source packages from trusted indexes and don’t rely on pip download --only-binary, exposure is effectively negligible, so this can be safely deprioritized.",
          "product_ids": [
            "Oracle-Linux-7:python3-pip-0:9.0.3-8.0.3.el7.noarch",
            "Oracle-Linux-7:python3-pip-0:9.0.3-8.0.3.el7.tuxcare.els1.noarch"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N",
            "version": "3.1"
          },
          "products": [
            "Oracle-Linux-7:python3-pip-0:9.0.3-8.0.3.el7.noarch",
            "Oracle-Linux-7:python3-pip-0:9.0.3-8.0.3.el7.tuxcare.els1.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate"
        }
      ]
    }
  ]
}