This update for python-pip fixes the following issues
CVE-2026-3219: pip doesn't reject concatenated ZIP (bsc#1262429).
CVE-2026-6357: pip self-update functionality can import newly installed modules after wheel installation
(bsc#1263442).
CVE-2026-8643: path traversal via malicious entry point name in pip wheel installation allows arbitrary file overwrite
(bsc#1266669).
Affected Packages
python311-pip
SUSE Linux Enterprise Desktop 15 SP7SUSE Linux Enterprise High Performance Computing 15 SP4SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOSSUSE Linux Enterprise High Performance Computing 15 SP4-LTSSSUSE Linux Enterprise High Performance Computing 15 SP5