==========================================================================
Ubuntu Security Notice USN-8010-1
February 04, 2026

python-pip vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS
- Ubuntu 16.04 LTS

Summary:

Several security issues were fixed in pip.

Software Description:
- python-pip: Python package installer

Details:

Several security issues were discovered in the libraries bundled in pip. An
attacker could possibly use these issues to perform a variety of attacks,
such as denial of service or arbitrary code execution.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 20.04 LTS
  python-pip-whl                  20.0.2-5ubuntu1.11+esm4
                                  Available with Ubuntu Pro
  python3-pip                     20.0.2-5ubuntu1.11+esm4
                                  Available with Ubuntu Pro

Ubuntu 18.04 LTS
  python-pip                      9.0.1-2.3~ubuntu1.18.04.8+esm8
                                  Available with Ubuntu Pro
  python-pip-whl                  9.0.1-2.3~ubuntu1.18.04.8+esm8
                                  Available with Ubuntu Pro
  python3-pip                     9.0.1-2.3~ubuntu1.18.04.8+esm8
                                  Available with Ubuntu Pro

Ubuntu 16.04 LTS
  python-pip                      8.1.1-2ubuntu0.6+esm12
                                  Available with Ubuntu Pro
  python-pip-whl                  8.1.1-2ubuntu0.6+esm12
                                  Available with Ubuntu Pro
  python3-pip                     8.1.1-2ubuntu0.6+esm12
                                  Available with Ubuntu Pro

In general, a standard system update will make all the necessary changes.

References:
  https://ubuntu.com/security/notices/USN-8010-1
  CVE-2025-47273, CVE-2025-66418, CVE-2026-21441

Attachment: signature.asc
Description: OpenPGP digital signature

Reply via email to