virtualenv’s Seed-Wheel Check Has a Custom-Index Exception
The PyPA advisory, dated 18 September 2026, rates unchecked network seed wheels Low for virtualenv through 21.7.11; 21.7.12 fixes it. The path covers periodic updates or --download; bundled wheels were already hashed. Substitution needs a compromised index, stale mirror or intercepted TLS path. The advisory identifies no victim.
The new PyPI digest check skips custom indexes set by PIP_INDEX_URL, PIP_EXTRA_INDEX_URL or PIP_INDEX, where rebuilt wheels may be intentional. This exception applies to CVE-2026-102930.
Decide which build path you own
BlackTree analysis: Ask build owners where seed wheels come from and which setting chooses that source. Record the version, wheel hash and approving owner for a representative build. A successful environment creation does not establish provenance.
Upgrade to 21.7.12 or later. If an index was demonstrably compromised, compare build records with trusted artefacts before deciding on rebuilds. Without evidence, do not label every older environment infected. Record the checked path in the patch ticket.
Sources
- PyPA advisory and 21.7.12 release, both dated 18 September 2026.


