{
	"document":{
		"aggregate_severity":{
			"namespace":"https://nvd.nist.gov/vuln-metrics/cvss",
			"text":"High"
		},
		"category":"csaf_vex",
		"csaf_version":"2.0",
		"distribution":{
			"tlp":{
				"label":"WHITE",
				"url":"https:/www.first.org/tlp/"
			}
		},
		"lang":"en",
		"notes":[
			{
				"text":"python-pip security update",
				"category":"general",
				"title":"Synopsis"
			},
			{
				"text":"An update for python-pip is now available for openEuler-22.03-LTS-SP4",
				"category":"general",
				"title":"Summary"
			},
			{
				"text":"pip is the package installer for Python. You can use pip to install packages from the Python Package Index and other indexes. %global bashcompdir %(b=$(pkg-config --variable=completionsdir bash-completion 2&gt;/dev/null); echo ${b:-/bash_completion.d}) Name:           python-pip Version:        23.3.1 Release:        6 Summary:        A tool for installing and managing Python packages License:        MIT and Python and ASL 2.0 and BSD and ISC and LGPLv2 and MPLv2.0 and (ASL 2.0 or BSD) URL:            http://www.pip-installer.org Source0:          Source1:        pip.loongarch.conf BuildArch:      noarch Patch1:         remove-existing-dist-only-if-path-conflicts. Patch6000:      dummy-certifi.patch Patch6001:      backport-CVE-2023-45803-Made-body-stripped-from-HTTP-requests.patch Patch6002:      backport-CVE-2024-37891-Strip-Proxy-Authorization-header-on-redirects.patch Patch6003:      backport-CVE-2024-47081.patch Patch6004:      backport-CVE-2025-50181.patch Patch6005:      backport-CVE-2025-8869.patch\n\nSecurity Fix(es):\n\nurllib3 is a user-friendly HTTP client library for Python. Starting in version 1.24 and prior to 2.6.0, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage and massive memory allocation for the decompressed data. This vulnerability is fixed in 2.6.0.(CVE-2025-66418)\n\nurllib3's streaming API is designed for the efficient handling of large HTTP responses by reading the content in chunks, rather than loading the entire response body into memory at once. urllib3 can perform decoding or decompression based on the HTTP Content-Encoding header (e.g., gzip, deflate, br, or zstd). When using the streaming API, the library decompresses only the necessary bytes, enabling partial content consumption. However, for HTTP redirect responses, the library would read the entire response body to drain the connection and decompress the content unnecessarily. This decompression occurred even before any read methods were called, and configured read limits did not restrict the amount of decompressed data. As a result, there was no safeguard against decompression bombs. A malicious server could exploit this to trigger excessive resource consumption on the client (high CPU usage and large memory allocations for decompressed data).(CVE-2026-21441)",
				"category":"general",
				"title":"Description"
			},
			{
				"text":"An update for python-pip is now available for openEuler-22.03-LTS-SP4.\n\nopenEuler Security has rated this update as having a security impact of high. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.",
				"category":"general",
				"title":"Topic"
			},
			{
				"text":"High",
				"category":"general",
				"title":"Severity"
			},
			{
				"text":"python-pip",
				"category":"general",
				"title":"Affected Component"
			}
		],
		"publisher":{
			"issuing_authority":"openEuler security committee",
			"name":"openEuler",
			"namespace":"https://www.openeuler.org",
			"contact_details":"openeuler-security@openeuler.org",
			"category":"vendor"
		},
		"references":[
			{
				"summary":"openEuler-SA-2026-1395",
				"category":"self",
				"url":"https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-1395"
			},
			{
				"summary":"CVE-2025-66418",
				"category":"self",
				"url":"https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-66418&packageName=python-pip"
			},
			{
				"summary":"CVE-2026-21441",
				"category":"self",
				"url":"https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-21441&packageName=python-pip"
			},
			{
				"summary":"nvd cve",
				"category":"external",
				"url":"https://nvd.nist.gov/vuln/detail/CVE-2025-66418"
			},
			{
				"summary":"nvd cve",
				"category":"external",
				"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-21441"
			},
			{
				"summary":"openEuler-SA-2026-1395 vex file",
				"category":"self",
				"url":"https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-1395.json"
			}
		],
		"title":"An update for python-pip is now available for openEuler-22.03-LTS-SP4",
		"tracking":{
			"initial_release_date":"2026-02-14T15:28:39+08:00",
			"revision_history":[
				{
					"date":"2026-02-14T15:28:39+08:00",
					"summary":"Initial",
					"number":"1.0.0"
				}
			],
			"generator":{
				"date":"2026-02-14T15:28:39+08:00",
				"engine":{
					"name":"openEuler CSAF Tool V1.0"
				}
			},
			"current_release_date":"2026-02-14T15:28:39+08:00",
			"id":"openEuler-SA-2026-1395",
			"version":"1.0.0",
			"status":"final"
		}
	},
	"product_tree":{
		"branches":[
			{
				"name":"openEuler",
				"category":"vendor",
				"branches":[
					{
						"name":"openEuler",
						"branches":[
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:22.03-LTS-SP4"
									},
									"product_id":"openEuler-22.03-LTS-SP4",
									"name":"openEuler-22.03-LTS-SP4"
								},
								"name":"openEuler-22.03-LTS-SP4",
								"category":"product_version"
							}
						],
						"category":"product_name"
					},
					{
						"name":"src",
						"branches":[
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:22.03-LTS-SP4"
									},
									"product_id":"python-pip-21.3.1-13.oe2203sp4.src.rpm",
									"name":"python-pip-21.3.1-13.oe2203sp4.src.rpm"
								},
								"name":"python-pip-21.3.1-13.oe2203sp4.src.rpm",
								"category":"product_version"
							}
						],
						"category":"architecture"
					},
					{
						"name":"noarch",
						"branches":[
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:22.03-LTS-SP4"
									},
									"product_id":"python-pip-help-21.3.1-13.oe2203sp4.noarch.rpm",
									"name":"python-pip-help-21.3.1-13.oe2203sp4.noarch.rpm"
								},
								"name":"python-pip-help-21.3.1-13.oe2203sp4.noarch.rpm",
								"category":"product_version"
							},
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:22.03-LTS-SP4"
									},
									"product_id":"python-pip-wheel-21.3.1-13.oe2203sp4.noarch.rpm",
									"name":"python-pip-wheel-21.3.1-13.oe2203sp4.noarch.rpm"
								},
								"name":"python-pip-wheel-21.3.1-13.oe2203sp4.noarch.rpm",
								"category":"product_version"
							},
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:22.03-LTS-SP4"
									},
									"product_id":"python3-pip-21.3.1-13.oe2203sp4.noarch.rpm",
									"name":"python3-pip-21.3.1-13.oe2203sp4.noarch.rpm"
								},
								"name":"python3-pip-21.3.1-13.oe2203sp4.noarch.rpm",
								"category":"product_version"
							}
						],
						"category":"architecture"
					}
				]
			}
		],
		"relationships":[
			{
				"relates_to_product_reference":"openEuler-22.03-LTS-SP4",
				"product_reference":"python-pip-21.3.1-13.oe2203sp4.src.rpm",
				"full_product_name":{
					"product_id":"openEuler-22.03-LTS-SP4:python-pip-21.3.1-13.oe2203sp4.src",
					"name":"python-pip-21.3.1-13.oe2203sp4.src as a component of openEuler-22.03-LTS-SP4"
				},
				"category":"default_component_of"
			},
			{
				"relates_to_product_reference":"openEuler-22.03-LTS-SP4",
				"product_reference":"python-pip-help-21.3.1-13.oe2203sp4.noarch.rpm",
				"full_product_name":{
					"product_id":"openEuler-22.03-LTS-SP4:python-pip-help-21.3.1-13.oe2203sp4.noarch",
					"name":"python-pip-help-21.3.1-13.oe2203sp4.noarch as a component of openEuler-22.03-LTS-SP4"
				},
				"category":"default_component_of"
			},
			{
				"relates_to_product_reference":"openEuler-22.03-LTS-SP4",
				"product_reference":"python-pip-wheel-21.3.1-13.oe2203sp4.noarch.rpm",
				"full_product_name":{
					"product_id":"openEuler-22.03-LTS-SP4:python-pip-wheel-21.3.1-13.oe2203sp4.noarch",
					"name":"python-pip-wheel-21.3.1-13.oe2203sp4.noarch as a component of openEuler-22.03-LTS-SP4"
				},
				"category":"default_component_of"
			},
			{
				"relates_to_product_reference":"openEuler-22.03-LTS-SP4",
				"product_reference":"python3-pip-21.3.1-13.oe2203sp4.noarch.rpm",
				"full_product_name":{
					"product_id":"openEuler-22.03-LTS-SP4:python3-pip-21.3.1-13.oe2203sp4.noarch",
					"name":"python3-pip-21.3.1-13.oe2203sp4.noarch as a component of openEuler-22.03-LTS-SP4"
				},
				"category":"default_component_of"
			}
		]
	},
	"vulnerabilities":[
		{
			"cve":"CVE-2025-66418",
			"notes":[
				{
					"text":"urllib3 is a user-friendly HTTP client library for Python. Starting in version 1.24 and prior to 2.6.0, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage and massive memory allocation for the decompressed data. This vulnerability is fixed in 2.6.0.",
					"category":"description",
					"title":"Vulnerability Description"
				}
			],
			"product_status":{
				"fixed":[
					"openEuler-22.03-LTS-SP4:python-pip-21.3.1-13.oe2203sp4.src",
					"openEuler-22.03-LTS-SP4:python-pip-help-21.3.1-13.oe2203sp4.noarch",
					"openEuler-22.03-LTS-SP4:python-pip-wheel-21.3.1-13.oe2203sp4.noarch",
					"openEuler-22.03-LTS-SP4:python3-pip-21.3.1-13.oe2203sp4.noarch"
				]
			},
			"remediations":[
				{
					"product_ids":[
						"openEuler-22.03-LTS-SP4:python-pip-21.3.1-13.oe2203sp4.src",
						"openEuler-22.03-LTS-SP4:python-pip-help-21.3.1-13.oe2203sp4.noarch",
						"openEuler-22.03-LTS-SP4:python-pip-wheel-21.3.1-13.oe2203sp4.noarch",
						"openEuler-22.03-LTS-SP4:python3-pip-21.3.1-13.oe2203sp4.noarch"
					],
					"details":"python-pip security update",
					"category":"vendor_fix",
					"url":"https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-1395"
				}
			],
			"scores":[
				{
					"cvss_v3":{
						"baseSeverity":"HIGH",
						"baseScore":7.5,
						"vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
						"version":"3.1"
					},
					"products":[
						"openEuler-22.03-LTS-SP4:python-pip-21.3.1-13.oe2203sp4.src",
						"openEuler-22.03-LTS-SP4:python-pip-help-21.3.1-13.oe2203sp4.noarch",
						"openEuler-22.03-LTS-SP4:python-pip-wheel-21.3.1-13.oe2203sp4.noarch",
						"openEuler-22.03-LTS-SP4:python3-pip-21.3.1-13.oe2203sp4.noarch"
					]
				}
			],
			"threats":[
				{
					"details":"High",
					"category":"impact"
				}
			],
			"title":"CVE-2025-66418"
		},
		{
			"cve":"CVE-2026-21441",
			"notes":[
				{
					"text":"urllib3's streaming API is designed for the efficient handling of large HTTP responses by reading the content in chunks, rather than loading the entire response body into memory at once. urllib3 can perform decoding or decompression based on the HTTP Content-Encoding header (e.g., gzip, deflate, br, or zstd). When using the streaming API, the library decompresses only the necessary bytes, enabling partial content consumption. However, for HTTP redirect responses, the library would read the entire response body to drain the connection and decompress the content unnecessarily. This decompression occurred even before any read methods were called, and configured read limits did not restrict the amount of decompressed data. As a result, there was no safeguard against decompression bombs. A malicious server could exploit this to trigger excessive resource consumption on the client (high CPU usage and large memory allocations for decompressed data).",
					"category":"description",
					"title":"Vulnerability Description"
				}
			],
			"product_status":{
				"fixed":[
					"openEuler-22.03-LTS-SP4:python-pip-21.3.1-13.oe2203sp4.src",
					"openEuler-22.03-LTS-SP4:python-pip-help-21.3.1-13.oe2203sp4.noarch",
					"openEuler-22.03-LTS-SP4:python-pip-wheel-21.3.1-13.oe2203sp4.noarch",
					"openEuler-22.03-LTS-SP4:python3-pip-21.3.1-13.oe2203sp4.noarch"
				]
			},
			"remediations":[
				{
					"product_ids":[
						"openEuler-22.03-LTS-SP4:python-pip-21.3.1-13.oe2203sp4.src",
						"openEuler-22.03-LTS-SP4:python-pip-help-21.3.1-13.oe2203sp4.noarch",
						"openEuler-22.03-LTS-SP4:python-pip-wheel-21.3.1-13.oe2203sp4.noarch",
						"openEuler-22.03-LTS-SP4:python3-pip-21.3.1-13.oe2203sp4.noarch"
					],
					"details":"python-pip security update",
					"category":"vendor_fix",
					"url":"https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-1395"
				}
			],
			"scores":[
				{
					"cvss_v3":{
						"baseSeverity":"HIGH",
						"baseScore":8.9,
						"vectorString":"CVSS:3.1/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
						"version":"3.1"
					},
					"products":[
						"openEuler-22.03-LTS-SP4:python-pip-21.3.1-13.oe2203sp4.src",
						"openEuler-22.03-LTS-SP4:python-pip-help-21.3.1-13.oe2203sp4.noarch",
						"openEuler-22.03-LTS-SP4:python-pip-wheel-21.3.1-13.oe2203sp4.noarch",
						"openEuler-22.03-LTS-SP4:python3-pip-21.3.1-13.oe2203sp4.noarch"
					]
				}
			],
			"threats":[
				{
					"details":"High",
					"category":"impact"
				}
			],
			"title":"CVE-2026-21441"
		}
	]
}