CVE-2026-59890CWE-176CWE-697

setuptools: MANIFEST.in exclusion bypass in sdist via Unicode normalization collision (NFC/NFD) on macOS APFS/HFS+

Medium · published July 8, 2026

CVSS v3.1
6.1
EPSS
0%
Percentile
33.8
In the wild
Unconfirmed
What it is

setuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. Prior to 83.0.0, FileList applied MANIFEST.in exclude, global-exclude, recursive-exclude, and prune directives by matching compiled glob patterns against on-disk file names without Unicode normalization, so on macOS APFS or HFS+ an NFD file name could bypass an NFC exclusion rule and be packed into a source distribution. This issue is fixed in version 83.0.0.

The record
Technical detail
CVSS v3.1
6.1 · MEDIUM
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N
CVSS v4.0
Not supplied
EPSS
0.00405 · 33.8th percentile
Weaknesses
CWE-176 · Improper Handling of Unicode Encoding; CWE-697 · Incorrect Comparison
Published
2026-07-08T16:02Z
EPSS history
Timeline
  • 08 JUL 16:02Z
    setuptools: MANIFEST.in exclusion bypass in sdist via Unicode normalization collision (NFC/NFD) on macOS APFS/HFS+
    cvelistv5