Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-6357

Опубликовано: 27 апр. 2026
Источник: debian
EPSS Низкий

Описание

pip prior to version 26.1 would run self-update check functionality after installing wheel files which required importing well-known Python modules names. These module imports were intentionally deferred to increase startup time of the pip CLI. The patch changes self-update functionality to run before wheels are installed to prevent newly-installed modules from being imported shortly after the installation of a wheel package. Users should still review package contents prior to installation.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
python-pipfixed26.1.1+dfsg-1package
python-pipno-dsatrixiepackage
python-pipno-dsabookwormpackage
python-pippostponedbullseyepackage

Примечания

  • https://github.com/pypa/pip/pull/13923

  • https://github.com/pypa/pip/commit/b369bfc96cc524e00c267e1693290e6599c36bad (26.1)

EPSS

Процентиль: 4%
0.00138
Низкий

Связанные уязвимости

ubuntu
3 месяца назад

pip prior to version 26.1 would run self-update check functionality after installing wheel files which required importing well-known Python modules names. These module imports were intentionally deferred to increase startup time of the pip CLI. The patch changes self-update functionality to run before wheels are installed to prevent newly-installed modules from being imported shortly after the installation of a wheel package. Users should still review package contents prior to installation.

CVSS3: 5.8
redhat
3 месяца назад

pip prior to version 26.1 would run self-update check functionality after installing wheel files which required importing well-known Python modules names. These module imports were intentionally deferred to increase startup time of the pip CLI. The patch changes self-update functionality to run before wheels are installed to prevent newly-installed modules from being imported shortly after the installation of a wheel package. Users should still review package contents prior to installation.

nvd
3 месяца назад

pip prior to version 26.1 would run self-update check functionality after installing wheel files which required importing well-known Python modules names. These module imports were intentionally deferred to increase startup time of the pip CLI. The patch changes self-update functionality to run before wheels are installed to prevent newly-installed modules from being imported shortly after the installation of a wheel package. Users should still review package contents prior to installation.

msrc
3 месяца назад

pip self-update functionality can import newly installed modules after wheel installation

github
3 месяца назад

pip Vulnerable to Inclusion of Functionality from Untrusted Control Sphere

EPSS

Процентиль: 4%
0.00138
Низкий