Repository navigation
chore(deps): Update dependency setuptools to v83 [SECURITY] - autoclosed - #1562
Closed
renovate[bot] wants to merge 1 commit into
Closed
renovate[bot] wants to merge 1 commit into
renovate[bot] wants to merge 1 commit into
Conversation
renovate
Bot
force-pushed
the
renovate/pypi-setuptools-vulnerability
branch
from
September 26, 2026 18:29
85b2dcf to
b8b879f
Compare
renovate
Bot
force-pushed
the
renovate/pypi-setuptools-vulnerability
branch
from
September 26, 2026 19:14
b8b879f to
bced1f7
Compare
renovate
Bot
force-pushed
the
renovate/pypi-setuptools-vulnerability
branch
from
September 26, 2026 19:21
bced1f7 to
44be814
Compare
renovate
Bot
force-pushed
the
renovate/pypi-setuptools-vulnerability
branch
from
September 26, 2026 20:05
44be814 to
9ae4d3e
Compare
renovate
Bot
force-pushed
the
renovate/pypi-setuptools-vulnerability
branch
from
September 26, 2026 20:07
9ae4d3e to
1e91397
Compare
Contributor
4 of 8 tasks
lusoris
pushed a commit
that referenced
this pull request
Oct 5, 2026
… defects on the known-upstream page The known-upstream page listed #1562 only. It now has a dated section for the GPU reports checked on 2026-10-05: - #1566 (fixed upstream by #1552): the CUDA motion kernel above 8 bits advanced a 16-bit pointer by the byte stride. Not affected: the fork's SAD kernel reads a row through a byte pointer (load_sample()), equal to the CPU in test_cuda_exact_twins, test_cuda_motion_tiny_frames and the depth and layout matrix; the planted upstream form fails above 8 bits and gives 26993 invalid reads under compute-sanitizer memcheck. - #1564 bugs 1 to 3 (CUDA masking border rows, per-warp rounding, x86 DWT last column) and its follow-ups: were affected, fixed, with the code and tests that hold each fix. docs/state.md records #1566 under "Confirmed not-affected".
lusoris
pushed a commit
to Tualua/vmafx
that referenced
this pull request
Oct 6, 2026
… defects on the known-upstream page (VMAFx#2178) * docs(upstream): record the CUDA 16-bit row-stride and integer ADM GPU defects on the known-upstream page The known-upstream page listed VMAFx#1562 only. It now has a dated section for the GPU reports checked on 2026-10-05: - VMAFx#1566 (fixed upstream by VMAFx#1552): the CUDA motion kernel above 8 bits advanced a 16-bit pointer by the byte stride. Not affected: the fork's SAD kernel reads a row through a byte pointer (load_sample()), equal to the CPU in test_cuda_exact_twins, test_cuda_motion_tiny_frames and the depth and layout matrix; the planted upstream form fails above 8 bits and gives 26993 invalid reads under compute-sanitizer memcheck. - VMAFx#1564 bugs 1 to 3 (CUDA masking border rows, per-warp rounding, x86 DWT last column) and its follow-ups: were affected, fixed, with the code and tests that hold each fix. docs/state.md records VMAFx#1566 under "Confirmed not-affected".
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
>=77.0.1→>=83.0.0setuptools has a path traversal vulnerability in PackageIndex.download that leads to Arbitrary File Write
BIT-setuptools-2025-47273 / CVE-2025-47273 / GHSA-5rjg-fvgr-3xxf / PYSEC-2025-49
More information
Details
Summary
A path traversal vulnerability in
PackageIndexwas fixed in setuptools version 78.1.1Details
Here: https://github.com/pypa/setuptools/blob/6ead555c5fb29bc57fe6105b1bffc163f56fd558/setuptools/package_index.py#L810C1-L825C88
os.path.join()discards the first argumenttmpdirif the second begins with a slash or drive letter.nameis derived from a URL without sufficient sanitization. While there is some attempt to sanitize by replacing instances of '..' with '.', it is insufficient.Risk Assessment
As easy_install and package_index are deprecated, the exploitation surface is reduced.
However, it seems this could be exploited in a similar fashion like GHSA-r9hx-vwmv-q579, and as described by POC 4 in GHSA-cx63-2mw6-8hw5 report: via malicious URLs present on the pages of a package index.
Impact
An attacker would be allowed to write files to arbitrary locations on the filesystem with the permissions of the process running the Python code, which could escalate to RCE depending on the context.
References
https://huntr.com/bounties/d6362117-ad57-4e83-951f-b8141c6e7ca5
https://github.com/pypa/setuptools/issues/4946
Severity
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:PReferences
This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).
BIT-setuptools-2025-47273 / CVE-2025-47273 / GHSA-5rjg-fvgr-3xxf / PYSEC-2025-49
More information
Details
setuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. A path traversal vulnerability in
PackageIndexis present in setuptools prior to version 78.1.1. An attacker would be allowed to write files to arbitrary locations on the filesystem with the permissions of the process running the Python code, which could escalate to remote code execution depending on the context. Version 78.1.1 fixes the issue.Severity
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HReferences
This data is provided by OSV and the PyPI Advisory Database (CC-BY 4.0).
setuptools: MANIFEST.in exclusion bypass in sdist via Unicode normalization collision (NFC/NFD) on macOS APFS/HFS+
BIT-setuptools-2026-59890 / CVE-2026-59890 / GHSA-h35f-9h28-mq5c / PYSEC-2026-3447
More information
Details
Summary
When building a source distribution (
python -m build --sdist/setup.py sdist), setuptools'FileListappliesMANIFEST.indirectives (exclude,global-exclude,recursive-exclude,prune) by matching a compiled glob against on-disk file names byte-for-byte, with no Unicode normalization. On normalization-preserving filesystems (notably macOS APFS and HFS+), a file written in NFD and aMANIFEST.inrule written in NFC refer to the same file but are byte-distinct, so the exclusion silently fails to match. A file the maintainer intended to exclude is then packed into the.tar.gzand, if published, uploaded to the public, immutable PyPI index.Details
File names in
FileList.filescome fromos.walk(setuptools/_distutils/filelist.py,_find_all_simple), so on APFS a file written NFD is offered to the matcher in NFD, while theMANIFEST.inpattern carries the author's editor form (typically NFC). The matching path performs no canonicalization:A rule written NFC (
café=63 61 66 c3 a9) does not match an on-disk name written NFD (café=63 61 66 65 cc 81), even though the filesystem treats the two as one file.A
unicodedata.normalize('NFD', ...)helper exists insetuptools/unicode_utils.py(decompose()), but it is never called in the manifest matching path, so neither the pattern nor the walked path is normalized before matching. The only normalization in this area,EggInfoCommand._manifest_normalize, usesfilesys_decode(bytes→str decode only, no NFC/NFD) and runs when writingSOURCES.txt, after matching has already occurred.Impact
MANIFEST.inexclusions are the documented mechanism maintainers use to keep secrets, local configs, and private fixtures out of the published sdist. A non-ASCII excluded file may be published to the public, immutable PyPI index despite the rule — an irreversible disclosure with no visual cue (NFC and NFD forms render identically). Exposure is filesystem-dependent and most relevant on macOS APFS/HFS+, where many maintainers build and publish. Pure-ASCII rules are unaffected.Proof of concept
With a project containing
MANIFEST.in:and an on-disk file
secret_café.txtwritten in NFD,python -m build --sdistpacks the secret file into the resulting.tar.gz, while an ASCII control file excluded by the same directive is correctly dropped — isolating the bypass to the NFC-pattern vs. NFD-name mismatch. Reproduced on macOS APFS with setuptools 82.0.1.Remediation
Normalize both the walked path and each
MANIFEST.inpattern to a single canonical form before matching, in bothsetuptools/command/egg_info.py(FileList) and the vendoredsetuptools/_distutils/filelist.py. For an exclusion list, err toward excluding more, and document thatMANIFEST.inmatching is normalization-insensitive on macOS.Credit
Reported by Tomas Illuminati. Coordinated via CERT/CC VINCE VU#604762.
Severity
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:NReferences
This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).
BIT-setuptools-2026-59890 / CVE-2026-59890 / GHSA-h35f-9h28-mq5c / PYSEC-2026-3447
More information
Details
setuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. Prior to 83.0.0, FileList applied MANIFEST.in exclude, global-exclude, recursive-exclude, and prune directives by matching compiled glob patterns against on-disk file names without Unicode normalization, so on macOS APFS or HFS+ an NFD file name could bypass an NFC exclusion rule and be packed into a source distribution. This issue is fixed in version 83.0.0.
Severity
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:NReferences
This data is provided by OSV and the PyPI Advisory Database (CC-BY 4.0).
Release Notes
pypa/setuptools (setuptools)
v83.0.0Compare Source
v82.0.1Compare Source
v82.0.0Compare Source
v81.0.0Compare Source
v80.10.2Compare Source
v80.10.1Compare Source
v80.9.0Compare Source
v80.8.0Compare Source
v80.7.1Compare Source
v80.7.0Compare Source
v80.6.0Compare Source
v80.4.0Compare Source
v80.3.1Compare Source
v80.3.0Compare Source
v80.2.0Compare Source
v80.1.0Compare Source
v80.0.1Compare Source
v80.0.0Compare Source
v79.0.1Compare Source
v79.0.0Compare Source
v78.1.1Compare Source
v78.1.0Compare Source
v78.0.2Compare Source
v78.0.1Compare Source
v77.0.3Compare Source
Configuration
📅 Schedule: (in timezone Europe/Vienna)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.