The Wheel Project maintains the wheel package format and tooling for Python distribution, a foundational component in the Python packaging ecosystem with broad downstream exposure. Its vulnerability footprint centers on the wheel package itself, with the durable signal drawn from input-handling weaknesses such as improper input validation, path-traversal conditions, and permission-assignment issues that affect archive extraction and file handling. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wheel Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-40898HIGH An issue discovered in Python Packaging Authority (PyPA) Wheel 0.37.1 and earlier allows remote attackers to cause a denial of service via attacker controlled input to wheel cli. | Dec 23, 2022 | 7.5 | 26 | NO | NO |
CVE-2026-24049MEDIUM wheel is a command line tool for manipulating Python wheel files, as defined in PEP 427. In versions 0.40.0 through 0.46.1, the unpack function is vulnerable to file permission mod | Jan 22, 2026 | 5.5 | 25 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wheel Project.
Media articles that mention a CVE ID that affects a product developed by Wheel Project — matched by CVE ID, not by vendor name.