216.73.217.22

CVE-2026-6357

· Published 27/04/2026 15:16 · Modified 27/04/2026 23:16

Labels: CVE-2026-6357 2026-04-27CVE-2026-6357CWE-829[email protected]

Essential information

Published
27/04/2026 15:16
Modified
27/04/2026 23:16
Author
Creator
CVSS
5.3 MEDIUM (v3) 5.3 MEDIUM (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

pip prior to version 26.1 would run self-update check functionality after installing wheel files which required importing well-known Python modules names. These module imports were intentionally deferred to increase startup time of the pip CLI. The patch changes self-update functionality to run before wheels are installed to prevent newly-installed modules from being imported shortly after the installation of a wheel package. Users should still review package contents prior to installation.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
python / pip cpe:2.3:a:python:pip:<26.1:*:*:*:*:*:*:*

References