CLEANSTART-2026-RT26999
Dashboard / Vulnerabilities / CLEANSTART-2026-RT26999
CLEANSTART-2026-RT26999
Summary: pip would incorrectly handle doubly-encoded package URLs from indexes allowing for files to be installed to arbitrary locations on disk even when installing wheels
Details: Multiple security vulnerabilities affect the k8s-sidecar package. pip would incorrectly handle doubly-encoded package URLs from indexes allowing for files to be installed to arbitrary locations on disk even when installing wheels. See references for individual vulnerability details.
References: https://github.com/cleanstart-dev/cleanstart-security-advisories/tree/main/advisories/2026/CLEANSTART-2026-RT26999.json, https://osv.dev/vulnerability/CVE-2024-35195, https://osv.dev/vulnerability/CVE-2024-47081, https://osv.dev/vulnerability/CVE-2025-8869, https://osv.dev/vulnerability/CVE-2026-13346, https://osv.dev/vulnerability/CVE-2026-1703, https://osv.dev/vulnerability/CVE-2026-25645, https://osv.dev/vulnerability/CVE-2026-3219, https://osv.dev/vulnerability/CVE-2026-44431, https://osv.dev/vulnerability/CVE-2026-44432, https://osv.dev/vulnerability/CVE-2026-6357, https://osv.dev/vulnerability/ghsa-58qw-9mgm-455v, https://osv.dev/vulnerability/ghsa-jp4c-xjxw-mgf9, https://osv.dev/vulnerability/ghsa-mf9v-mfxr-j63j, https://osv.dev/vulnerability/ghsa-qccp-gfcp-xxvc, https://nvd.nist.gov/vuln/detail/CVE-2024-35195, https://nvd.nist.gov/vuln/detail/CVE-2024-47081, https://nvd.nist.gov/vuln/detail/CVE-2025-8869, https://nvd.nist.gov/vuln/detail/CVE-2026-13346, https://nvd.nist.gov/vuln/detail/CVE-2026-1703, https://nvd.nist.gov/vuln/detail/CVE-2026-25645, https://nvd.nist.gov/vuln/detail/CVE-2026-3219, https://nvd.nist.gov/vuln/detail/CVE-2026-44431, https://nvd.nist.gov/vuln/detail/CVE-2026-44432, https://nvd.nist.gov/vuln/detail/CVE-2026-6357
Affected packages
Package
Name: k8s-sidecar
Purl:
Affected ranges
Type: ECOSYSTEM
Events:
