Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
PyPI Restricts Older Release File Uploads to Boost Security

PyPI Restricts Older Release File Uploads to Boost Security

Posted on July 27, 2026 By CWS

The Python Package Index (PyPI) has implemented a significant security measure to prevent malicious file uploads to existing package versions. With this new policy, uploads of new files to package releases older than 14 days are now restricted. This step is aimed at thwarting potential attacks where compromised tokens or workflows could be exploited to add harmful files to established Python packages.

Understanding the New Policy

As of July 8, 2022, PyPI’s Warehouse codebase enforces a rule that blocks uploads for any release older than two weeks. This change addresses a critical software supply-chain vulnerability by eliminating “open-ended” release possibilities. Previously, package maintainers enjoyed the flexibility of updating files for an existing release at any given time.

While this capability was beneficial for improving compatibility with new Python versions, it also posed a security risk. Attackers gaining access to API tokens or CI/CD pipelines could exploit this flexibility to introduce malicious files without altering the version number. This made detecting compromised packages during standard updates particularly challenging.

Impact and Rationale

PyPI has stated that, to its knowledge, this specific vulnerability has not been exploited by attackers in the past. However, the absence of technical barriers meant it remained a latent risk. The importance of the new rule was underscored by incidents involving popular packages like LiteLLM and Telnyx, which demonstrated the potential for supply-chain attacks.

With the new restrictions, any unauthorized file additions to older releases are effectively prevented, forcing maintainers to issue a new version if they need to support newer Python releases. This change simplifies the incident response process by ensuring all files within a release are legitimate, reducing user uncertainty regarding package safety.

Community and Future Developments

Before implementing this policy, PyPI conducted an analysis of historical publishing patterns. Among the top 15,000 packages, only 56 had added files after the initial release beyond the 14-day window, indicating minimal disruption for most maintainers. The change was also discussed at the Packaging Summit during PyCon US 2022, where it received general support.

Currently, this restriction serves as a practical security measure, but PyPI advises against considering it a formal guarantee of a release’s state. The platform plans to introduce more comprehensive definitions and controls through the proposed Upload 2.0 API and PEP 694, which will provide clearer semantics around open and closed releases.

This proactive step by PyPI significantly mitigates the risk of package poisoning, ensuring a safer environment for Python developers globally.

Cyber Security News Tags:API security, Cybersecurity, developer security, file uploads, package management, package security, PyPI, Python packages, software supply chain, supply chain attacks

Post navigation

Previous Post: Critical ChatGPT AgentForger Exploit Fixed by OpenAI
Next Post: TELESHIM Exploits Telegram for C2 in Middle East Attacks

Related Posts

New Linux Malware With Weaponized RAR Archive Deploys VShell Backdoor New Linux Malware With Weaponized RAR Archive Deploys VShell Backdoor Cyber Security News
Google Enhances Security, Blocks 1.75 Million Malicious Apps Google Enhances Security, Blocks 1.75 Million Malicious Apps Cyber Security News
GitHub Authentication Glitch Impacts Automation Services GitHub Authentication Glitch Impacts Automation Services Cyber Security News
NightSpire Ransomware Group Claims to Exploit The Vulnerabilities of Orgs to Infiltrate Their Systems NightSpire Ransomware Group Claims to Exploit The Vulnerabilities of Orgs to Infiltrate Their Systems Cyber Security News
SmartApeSG Campaign Exploits ClickFix for Malware Spread SmartApeSG Campaign Exploits ClickFix for Malware Spread Cyber Security News
AI ‘Intelligent Worm’ Threatens Cybersecurity Evolution AI ‘Intelligent Worm’ Threatens Cybersecurity Evolution Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • TELESHIM Exploits Telegram for C2 in Middle East Attacks
  • PyPI Restricts Older Release File Uploads to Boost Security
  • Critical ChatGPT AgentForger Exploit Fixed by OpenAI
  • NodeBB Vulnerabilities Expose Private Chats and Forums
  • MCBS Cyberattack Exposes Data of Over 1.2 Million

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • TELESHIM Exploits Telegram for C2 in Middle East Attacks
  • PyPI Restricts Older Release File Uploads to Boost Security
  • Critical ChatGPT AgentForger Exploit Fixed by OpenAI
  • NodeBB Vulnerabilities Expose Private Chats and Forums
  • MCBS Cyberattack Exposes Data of Over 1.2 Million

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark