CVE-2026-22702: 
Python vulnerability analysis and mitigation

Overview

CVE-2026-22702 is a TOCTOU (Time-of-Check-Time-of-Use) vulnerability in the virtualenv Python tool that allows local attackers to perform symlink-based attacks on directory creation operations. It affects all versions of virtualenv prior to 20.36.1 and was disclosed on January 9–10, 2026, by researcher @tsigouris007. The vulnerability carries a CVSS v3.1 base score of 4.5 (Medium) (Github Advisory). Downstream products including Microsoft's CBL-Mariner/Azure Linux packages and IBM Cloud Pak for Business Automation components are also affected (Microsoft, IBM Advisory).

Technical details

The root cause lies in two check-then-act patterns (CWE-362, CWE-59) in virtualenv's source code: src/virtualenv/app_data/__init__.py checks for directory existence with os.path.isdir() before calling os.makedirs(), and src/virtualenv/util/lock.py applies the same pattern when creating parent directories for lock files. A local attacker can exploit the race window between the existence check and directory creation by placing a symlink at the target path, redirecting virtualenv's app_data or lock file operations to an attacker-controlled location. The fix replaces both patterns with atomic os.makedirs(..., exist_ok=True) calls, which eliminate the TOCTOU window at the OS level (Github PR #3013, Github Advisory).

Impact

Successful exploitation can result in cache poisoning (corrupting wheels or Python metadata), information disclosure (reading sensitive cached data or metadata), lock bypass (controlling lock file semantics to cause concurrent access violations), and denial of service via lock starvation. The impact is limited to the local system and requires the attacker to already have low-privileged local access, making lateral movement unlikely; however, on multi-user systems or CI/CD environments where VIRTUALENV_OVERRIDE_APP_DATA points to a shared or user-writable location, the blast radius is broader (Github Advisory).

Exploitability

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the time of writing (Github Advisory). The EPSS score is approximately 0.01% (1st percentile), indicating a very low probability of near-term exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires local access, low privileges, and the ability to win a timing race, making opportunistic exploitation difficult.

Exploitation steps

  1. Reconnaissance: Identify a target multi-user system running a vulnerable version of virtualenv (< 20.36.1) where the attacker has local, low-privileged access and write access to shared temporary directories or the VIRTUALENV_OVERRIDE_APP_DATA path.
  2. Monitor target path: Continuously monitor the filesystem for the moment virtualenv performs its os.path.isdir() check on the app_data directory or lock file parent directory (e.g., using inotifywait on Linux).
  3. Win the race window: Immediately after the existence check returns false but before os.makedirs() executes, create a symlink at the target path pointing to an attacker-controlled directory (e.g., ln -s /tmp/attacker_dir /home/victim/.local/share/virtualenv).
  4. Redirect operations: Virtualenv proceeds to write cache files (wheels, Python metadata) or lock files into the attacker-controlled location, enabling cache poisoning, data reading, or lock file manipulation.
  5. Achieve objective: Depending on the attack goal — read sensitive cached metadata (information disclosure), inject malicious wheels into the cache (cache poisoning), or manipulate lock files to cause denial of service or concurrent access violations (Github PR #3013, Github Advisory).

Indicators of compromise

  • File System: Unexpected symlinks in virtualenv app_data directories (e.g., ~/.local/share/virtualenv/ or the path set by VIRTUALENV_OVERRIDE_APP_DATA) pointing to unusual or attacker-controlled locations; unexpected symlinks in lock file parent directories used by virtualenv.
  • File System: Presence of unexpected or modified wheel files or Python metadata in the virtualenv cache directory, potentially indicating cache poisoning.
  • Logs: Virtualenv log entries (e.g., could not create app data folder) appearing unexpectedly, which may indicate failed or redirected directory creation attempts.
  • Process: Unusual inotifywait, inotify-based monitoring processes, or rapid file creation activity in shared temporary directories coinciding with virtualenv invocations, potentially indicating a race condition exploit attempt.

Mitigation and workarounds

Upgrade virtualenv to version 20.36.2 or later, which replaces the vulnerable check-then-act patterns with atomic os.makedirs(..., exist_ok=True) operations (Github Advisory, Github PR #3013). IBM has addressed this in IBM Cloud Pak for Business Automation iFixes for April 2026 (IBM Advisory). If immediate patching is not possible, apply the following workarounds:

  • Set VIRTUALENV_OVERRIDE_APP_DATA to a directory owned exclusively by the current user with permissions 0700.
  • Avoid running virtualenv in shared temporary directories where other local users have write access.
  • Use separate OS user accounts for different projects to isolate app_data directories.

Community reactions

The vulnerability was reported by security researcher @tsigouris007 and patched by virtualenv maintainer Bernát Gábor (gaborbernat) on January 9, 2026, the same day it was disclosed — indicating a coordinated, responsible disclosure process (Github PR #3013). The advisory was quickly picked up by downstream package maintainers across numerous open-source projects, with many dependency bump PRs appearing within days of disclosure. No significant broader media coverage or notable public researcher commentary beyond the GitHub advisory thread has been identified.

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

python-virtualenv

Affected

sid

python-virtualenv: 20.36.1+ds-1

Fixed

trixie

python-virtualenv: 20.31.2+ds-1+deb13u1

Fixed

Ubuntu

Unknown

bionic (esm-apps)

python-virtualenv

Unknown

devel

python-virtualenv

Not Affected

focal (esm-apps)

python-virtualenv

Unknown

jammy

python-virtualenv

Unknown

jammy (esm-apps)

python-virtualenv

Unknown

noble

python-virtualenv

Unknown

noble (esm-apps)

python-virtualenv

Unknown

resolute

python-virtualenv

Unknown

RHEL / CentOS

Affected

RHEL 8

rhel8/python-36

Affected

Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-v2f8-6655-7grjCRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
CVE-2026-105782HIGH7.5
  • Python logoPython
  • scrapy
NoYesOct 06, 2026
GHSA-v853-p72q-4cfwHIGH7.5
  • Python logoPython
  • quart
NoYesOct 05, 2026
CVE-2026-105751MEDIUM6.9
  • Python logoPython
  • docling
NoYesOct 05, 2026
CVE-2026-105750MEDIUM5.9
  • Python logoPython
  • docling
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management