Disclosure summary
A flaw was found in python-pip in the way it handled Unicode separators in git references. A remote attacker could possibly use this issue to install a different revision on a repository. The highest threat from this vulnerability is to data integrity. This is fixed in python-pip version 21.1.
Source-reported weakness categories
CWE-20, NVD-CWE-noinfo
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
NIST National Vulnerability Database · NVD-CVE-2021-3572
Open original source · Updated Oct 08, 2026
Only CPE matches marked vulnerable=true are indexed. AND/OR platform conditions must be checked in the original NVD record.
| Vendor | Product / association | Version / bounds |
|---|---|---|
| pypa | pip | * {"versionEndExcluding":"21.1"} |
| oracle | agile_product_lifecycle_management | 9.3.6 |
| oracle | communications_cloud_native_core_network_function_cloud_native_environment | 1.10.0 |
| oracle | communications_cloud_native_core_network_function_cloud_native_environment | 22.1.0 |
| oracle | communications_cloud_native_core_policy | 1.15.0 |
| oracle | communications_cloud_native_core_policy | 22.1.3 |
Original records & references
- NIST NVD record
- CVE Program record
- bugzilla.redhat.com — Issue Tracking, Patch, Third Party Advisory
- security.netapp.com
- www.oracle.com — Patch, Third Party Advisory
- www.oracle.com — Patch, Third Party Advisory
- bugzilla.redhat.com — Issue Tracking, Patch, Third Party Advisory
- security.netapp.com
- www.oracle.com — Patch, Third Party Advisory
- www.oracle.com — Patch, Third Party Advisory
PUBLISHED 2021-11-10T13:15:09-05:00
MODIFIED 2026-10-08T17:17:40-04:00
INGESTED 2026-10-10T20:50:20-04:00