Advisory Database
  • Advisories
  • Dependency Scanning
  1. pypi
  2. ›
  3. virtualenv
  4. ›
  5. CVE-2026-102938

CVE-2026-102938: virtualenv writes prompt values into pyvenv.cfg without sanitizing line boundaries, allowing configuration injection

September 30, 2026

pyvenv.cfg is a line-based format with no escape syntax. PyEnvCfg.write() wrote values verbatim, while PyEnvCfg._read_values() parses the file with str.splitlines(). A value containing a line boundary therefore became additional configuration lines, and because reading is last-wins, the injected keys replaced any key written earlier in the file.

References

  • github.com/advisories/GHSA-9h9j-4vrj-gf7g
  • github.com/pypa/advisory-database/tree/main/vulns/virtualenv/PYSEC-2026-4012.yaml
  • github.com/pypa/virtualenv/commit/a30f995461043acb6cacbf3a890951563ccf7140
  • github.com/pypa/virtualenv/pull/3247
  • github.com/pypa/virtualenv/releases/tag/21.7.11
  • github.com/pypa/virtualenv/security/advisories/GHSA-9h9j-4vrj-gf7g
  • nvd.nist.gov/vuln/detail/CVE-2026-102938
  • pypi.org/project/virtualenv

Code Behaviors & Features

Detect and mitigate CVE-2026-102938 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 21.7.11

Fixed versions

  • 21.7.11

Solution

Upgrade to version 21.7.11 or above.

Impact 6.6 MEDIUM

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:L

Learn more about CVSS

Weakness

  • CWE-93: Improper Neutralization of CRLF Sequences ('CRLF Injection')

Source file

pypi/virtualenv/CVE-2026-102938.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Thu, 01 Oct 2026 12:20:15 +0000.