Get real-time updates on Telegram
CVE-2026-102937: azl3 python-pip 24.2-10 on Azure Linux 3.0 (exact versions not specified); +14 more affected products
CVE-2026-102937 affects azl3 python-pip 24.2-10 on Azure Linux 3.0. EPSS 0.0014 (percentile 0.02829), scored 2026-10-05. Fixed version: 21.7.12-r0. Fixed version: 21.7.12-r0. Fixed version: 21.7.12-r0. Fixed version: 21.7.12-r0. Fixed version: 21.7.12-r0. Fixed version: 21.7.12-r0. Fixed version: 21.7.12-r0. Fixed version: 21.7.12-r0. Fixed version: 21.7.12-r0. Fixed version: 21.7.12-r0. Fixed version: 21.7.12-r0. Fixed version: 21.7.12-r0. Fixed version: 21.7.12-r0.
Affected technology
azl3 python-pip 24.2-10 on Azure Linux 3.0 · Exact affected versions not specified by the source
Microsoft
azl3 python-virtualenv 20.36.1-6 on Azure Linux 3.0 · Exact affected versions not specified by the source
Microsoft
py3-supported-virtualenv · Exact affected versions not specified by the source
Vendor not specified by the source
py3-virtualenv · Exact affected versions not specified by the source
Vendor not specified by the source
py3-virtualenv-auto · Exact affected versions not specified by the source
Vendor not specified by the source
py3.10-virtualenv · Exact affected versions not specified by the source
Vendor not specified by the source
py3.10-virtualenv-bin · Exact affected versions not specified by the source
Vendor not specified by the source
py3.11-virtualenv · Exact affected versions not specified by the source
Vendor not specified by the source
py3.11-virtualenv-bin · Exact affected versions not specified by the source
Vendor not specified by the source
py3.12-virtualenv · Exact affected versions not specified by the source
Vendor not specified by the source
py3.12-virtualenv-bin · Exact affected versions not specified by the source
Vendor not specified by the source
py3.13-virtualenv · Exact affected versions not specified by the source
Vendor not specified by the source
py3.13-virtualenv-bin · Exact affected versions not specified by the source
Vendor not specified by the source
py3.14-virtualenv · Exact affected versions not specified by the source
Vendor not specified by the source
py3.14-virtualenv-bin · Exact affected versions not specified by the source
Vendor not specified by the source
Component: Not specified by the source
What an attacker can do
The source does not specify what an attacker can achieve.
- Product
- azl3 python-pip 24.2-10 on Azure Linux 3.0
- CCR priority
- 0.0 /100 (P5)
- EPSS
- 0.0014 · percentile 0.02829 · 2026-10-05
- KEV
- no
Provenance
- Microsoft MSRC Security Update Guide (CVRF) · Source record · observed 2026-10-04 07:08:49.022374+00:00 UTC
- OSV.dev · Source record · observed 2026-10-06 17:58:42.508367+00:00 UTC
- FIRST EPSS daily exploit-probability · Source record · observed 2026-10-06 09:23:48.197899+00:00 UTC
Stable permalink: https://cybercodered.org/item/cve-cve-2026-102937.html