python-pip: when --extra-index-url option is used and package does not already exist in the public index, the installation of malicious package with arbitrary version number is possible.
Published May 8, 2020
7.8
HIGHCVSS 3.1
EPSS 1.78%
Description
An issue was discovered in pip (all versions) because it installs the version with the highest version number, even if the user had intended to obtain a private package from a private index. This only affects use of the --extra-index-url option, and exploitation requires that the package does not already exist in the public index (and thus the attacker can put the package there with an arbitrary version number). NOTE: it has been reported that this is intended functionality and the user is responsible for using --extra-index-url securely
Affected products
No data.
No data.
Red Hat Enterprise Linux 7
python-pip
Will not fix
Red Hat Enterprise Linux 8
python-pip
Will not fix
Red Hat Quay 3
python27-python-pip
Will not fix
Red Hat Software Collections
python27-python-pip
Will not fix
Red Hat Software Collections
rh-python36-python-pip
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 7 | python-pip | Will not fix | n/a |
| Red Hat Enterprise Linux 8 | python-pip | Will not fix | n/a |
| Red Hat Quay 3 | python27-python-pip | Will not fix | n/a |
| Red Hat Software Collections | python27-python-pip | Will not fix | n/a |
| Red Hat Software Collections | rh-python36-python-pip | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Although this issue affects versions of pip shipped with Red Hat Enterprise Linux, Red Hat Software Collections, and Red Hat CodeReady Workspaces, according to the pip documentation, this behavior is intentional when using the --extra-index-url flag, as pip installs the version with the highest version number. As such, Red Hat Product Security has classified this as a low-severity issue, given that it is the intended functionality of pip and requires specific conditions for potential exploitation.
Red Hat mitigation
To protect from any unintended behavior, use --index-url and do not use --extra-index-url OR explicitly set --index-url and use --extra-index-url.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
No CVSS v3.0 score for this CVE.
AV:N/AC:M/Au:N/C:P/I:P/A:P
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
TotalDecision
n/aAssessed Apr 15, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 2, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
- EPSS v4
Percentile over time
- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
- EPSS v4
Table of values (44 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 2, 2026 | 1.78% (0.01780) | 77.47th | v5 (v2026.06.15) |
| Jun 15, 2026 | 1.74% (0.01736) | 74.66th | v5 (v2026.06.15) |
| May 3, 2026 | 3.82% (0.03825) | 88.19th | v4 (v2025.03.14) |
| Mar 15, 2026 | 1.71% (0.01710) | 82.13th | v4 (v2025.03.14) |
| Mar 4, 2026 | 2.72% (0.02721) | 85.68th | v4 (v2025.03.14) |
| Mar 1, 2026 | 1.70% (0.01704) | 82.09th | v4 (v2025.03.14) |
| Feb 4, 2026 | 2.72% (0.02721) | 85.58th | v4 (v2025.03.14) |
| Feb 1, 2026 | 1.70% (0.01704) | 81.97th | v4 (v2025.03.14) |
| Jan 4, 2026 | 2.89% (0.02885) | 85.90th | v4 (v2025.03.14) |
| Jan 1, 2026 | 1.26% (0.01261) | 79.06th | v4 (v2025.03.14) |
| Dec 4, 2025 | 2.31% (0.02306) | 84.25th | v4 (v2025.03.14) |
| Dec 1, 2025 | 1.00% (0.00996) | 76.38th | v4 (v2025.03.14) |
| Nov 21, 2025 | 2.31% (0.02306) | 84.24th | v4 (v2025.03.14) |
| Nov 18, 2025 | 0.54% (0.00543) | 65.11th | v4 (v2025.03.14) |
| Nov 4, 2025 | 2.31% (0.02306) | 84.20th | v4 (v2025.03.14) |
| Nov 1, 2025 | 1.00% (0.00996) | 76.34th | v4 (v2025.03.14) |
| Oct 4, 2025 | 3.21% (0.03215) | 86.54th | v4 (v2025.03.14) |
| Oct 1, 2025 | 1.38% (0.01376) | 79.67th | v4 (v2025.03.14) |
| Sep 4, 2025 | 2.54% (0.02537) | 84.91th | v4 (v2025.03.14) |
| Sep 1, 2025 | 1.02% (0.01017) | 76.41th | v4 (v2025.03.14) |
| Aug 5, 2025 | 2.54% (0.02537) | 84.85th | v4 (v2025.03.14) |
| Aug 1, 2025 | 1.02% (0.01017) | 76.37th | v4 (v2025.03.14) |
| Jul 6, 2025 | 2.54% (0.02537) | 84.79th | v4 (v2025.03.14) |
| Jul 1, 2025 | 1.38% (0.01376) | 79.44th | v4 (v2025.03.14) |
| Jun 26, 2025 | 3.21% (0.03215) | 86.48th | v4 (v2025.03.14) |
| Jun 24, 2025 | 1.38% (0.01376) | 79.35th | v4 (v2025.03.14) |
| Jun 4, 2025 | 3.21% (0.03215) | 86.44th | v4 (v2025.03.14) |
| Jun 1, 2025 | 1.38% (0.01376) | 79.38th | v4 (v2025.03.14) |
| May 4, 2025 | 3.21% (0.03215) | 86.35th | v4 (v2025.03.14) |
| May 1, 2025 | 1.38% (0.01376) | 79.29th | v4 (v2025.03.14) |
| Mar 26, 2025 | 2.54% (0.02537) | 83.95th | v4 (v2025.03.14) |
| Mar 25, 2025 | 1.02% (0.01017) | 75.08th | v4 (v2025.03.14) |
| Mar 24, 2025 | 2.54% (0.02537) | 84.03th | v4 (v2025.03.14) |
| Mar 23, 2025 | 1.02% (0.01017) | 72.63th | v4 (v2025.03.14) |
| Mar 21, 2025 | 2.54% (0.02537) | 84.14th | v4 (v2025.03.14) |
| Mar 20, 2025 | 1.02% (0.01017) | 75.27th | v4 (v2025.03.14) |
| Mar 17, 2025 | 2.54% (0.02537) | 84.40th | v4 (v2025.03.14) |
| Jul 20, 2024 | 0.11% (0.00112) | 45.05th | v3 (v2023.03.01) |
| Jun 26, 2024 | 0.11% (0.00112) | 44.89th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.11% (0.00112) | 42.88th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.02% (0.01018) | 40.69th | v2 (v2022.01.01) |
| Feb 4, 2022 | 1.02% (0.01018) | 19.50th | v2 (v2022.01.01) |
| Feb 3, 2022 | 1.04% (0.01040) | 28.32th | v5 (v2026.06.15) |
| Apr 14, 2021 | 1.04% (0.01040) | 0.00th | v1 |
References (7)
- https://access.redhat.com/security/cve/CVE-2018-20225 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1835736 x_refsource_MISCIssue Tracking
- https://cowlicks.website/posts/arbitrary-code-execution-from-pips-extra-index-url.html x_refsource_MISCThird Party Advisory
- https://lists.apache.org/thread.html/rb1adce798445facd032870d644eb39c4baaf9c4a7dd5477d12bb6ab2%40%3Cgithub.arrow.apache.org%3E mailing-listx_refsource_MLIST
- https://nvd.nist.gov/vuln/detail/CVE-2018-20225
- https://pip.pypa.io/en/stable/news/ x_refsource_MISCRelease NotesVendor Advisory
- https://www.cve.org/CVERecord?id=CVE-2018-20225
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2018-20225 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1835736 | x_refsource_MISCIssue Tracking | |
| https://cowlicks.website/posts/arbitrary-code-execution-from-pips-extra-index-url.html | x_refsource_MISCThird Party Advisory | |
| https://lists.apache.org/thread.html/rb1adce798445facd032870d644eb39c4baaf9c4a7dd5477d12bb6ab2%40%3Cgithub.arrow.apache.org%3E | mailing-listx_refsource_MLIST | |
| https://nvd.nist.gov/vuln/detail/CVE-2018-20225 | ||
| https://pip.pypa.io/en/stable/news/ | x_refsource_MISCRelease NotesVendor Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2018-20225 |
Change history (0)
No recorded changes yet.