A flaw was found in pulp-python's PyPI simple index. Project names are written into the HTML index without escaping. A user who can publish a Python package can store markup in the package name. A person who opens that index in a browser runs the markup in the origin that served the page, and the attacker or user can take limited actions as that person on that site during the visit. The flaw does not run commands on the server.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 07 Oct 2026 12:30:00 +0000

Type Values Removed Values Added
Description A flaw was found in pulp-python's PyPI simple index. Project names are written into the HTML index without escaping. A user who can publish a Python package can store markup in the package name. A person who opens that index in a browser runs the markup in the origin that served the page, and the attacker or user can take limited actions as that person on that site during the visit. The flaw does not run commands on the server.
Title pulp_python: Simple index renders project names without HTML escaping
Weaknesses CWE-79
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}

threat_severity

Moderate


Projects

Sign in to view the affected projects.

cve-icon MITRE

No data.

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-10-07T05:34:00Z

Links: CVE-2026-103871 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T13:30:17Z

Weaknesses