天下漏洞,尽知其名
HIGH 重点关注

CVE-2026-102930 virtualenv 种子 wheel 校验缺失漏洞

影响攻击者可向新建虚拟环境植入被篡改的 pip/setuptools 包

AI 研判

virtualenv 是用于创建隔离 Python 虚拟环境的工具。在 21.7.12 之前,download_wheel() 在获取用于定期更新或 --download 选项的 pip、setuptools 种子 wheel 时,未像内置 wheel 那样通过 BUNDLE_SHA256 进行权威摘要校验。被攻陷的索引、过期镜像或 TLS 中间人可替换 wheel,virtualenv 会将其缓存并植入后续创建的虚拟环境。

影响范围

virtualenv

virtualenv 21.7.12 之前的版本;使用自定义索引(PIP_INDEX_URL、PIP_EXTRA_INDEX_URL 或 PIP_INDEX)时校验被有意跳过。

漏洞详情

漏洞类型为供应链完整性校验缺失(依赖包未验证)。成因是 download_wheel() 对动态下载的种子 wheel 缺少与内置 wheel 等价的 BUNDLE_SHA256 摘要比对,仅在默认 PyPI 路径下校验。攻击者通过控制索引、镜像或拦截 TLS,以相同发行版名、版本和文件名替换 wheel,即可让恶意包被缓存并注入新环境。

利用条件与风险

利用前提是攻击者能控制或劫持 pip 索引源(自定义索引、过期镜像或 TLS 中间人)。一旦成功,后续创建的虚拟环境会携带被篡改的 pip/setuptools,可能导致任意代码执行,供应链风险较高。

修复建议

升级至 virtualenv 21.7.12 或更高版本以启用种子 wheel 摘要校验。临时缓解措施:仅使用可信索引源,避免配置不受控的自定义 PIP_INDEX_URL/PIP_EXTRA_INDEX_URL,并确保 TLS 链路安全。

原始情报

virtualenv is a tool for creating isolated virtual python environments. Prior to 21.7.12, download_wheel() accepts pip and setuptools seed wheels fetched for periodic updates or the –download option without checking their bytes against an authoritative digest equivalent to the embedded wheels’ BUNDLE_SHA256 verification. A compromised index, stale mirror, or intercepted TLS connection can substitute a different wheel under the requested distribution, version, and filename, after which virtualenv caches and seeds the attacker-controlled wheel into subsequently created environments. The verification applies to the default PyPI path and is intentionally skipped when PIP_INDEX_URL, PIP_EXTRA_INDEX_URL, or PIP_INDEX configures a custom index that may legitimately publish rebuilt wheels. This issue is fixed in version 21.7.12.