Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

fstec логотип

BDU:2026-09786

Опубликовано: 27 апр. 2026
Источник: fstec
CVSS3: 5.8
CVSS2: 6.2
EPSS Низкий

Описание

Уязвимость модуля pip языка программирования Python связана с включением функций из недостоверной контролируемой области. Эксплуатация уязвимости может позволить нарушителю выполнить произвольный код

Вендор

Red Hat Inc.
ООО «Ред Софт»
Python Software Foundation

Наименование ПО

Red Hat Enterprise Linux
OpenShift Container Platform
Red Hat Quay
Red Hat Satellite
Migration Toolkit for Virtualization
OpenShift Dev Spaces
Red Hat Developer Hub
Red Hat OpenShift Lightspeed
Red Hat Trusted Artifact Signer
Red Hat AI Inference Server
Openshift Service Mesh
РЕД ОС
Red Hat Enterprise Linux AI
Service Telemetry Framework
Discovery
Ansible Automation Platform
Pen Drive Powered by Red Hat Lightspeed
Red Hat OpenShift AI
Migration Toolkit for Applications
Exploit Intelligence
Python-pip

Версия ПО

8 (Red Hat Enterprise Linux)
4 (OpenShift Container Platform)
3 (Red Hat Quay)
6 (Red Hat Satellite)
9 (Red Hat Enterprise Linux)
- (Migration Toolkit for Virtualization)
- (OpenShift Dev Spaces)
- (Red Hat Developer Hub)
- (Red Hat OpenShift Lightspeed)
- (Red Hat Trusted Artifact Signer)
10 (Red Hat Enterprise Linux)
- (Red Hat AI Inference Server)
3 (Openshift Service Mesh)
8.0 (РЕД ОС)
3 (Red Hat Enterprise Linux AI)
1.5 (Service Telemetry Framework)
2 (Discovery)
2 (Ansible Automation Platform)
- (Pen Drive Powered by Red Hat Lightspeed)
- (Red Hat OpenShift AI)
8 (Migration Toolkit for Applications)
- (Exploit Intelligence)
до 26.1 (Python-pip)

Тип ПО

Операционная система
Прикладное ПО информационных систем
ПО виртуализации/ПО виртуального программно-аппаратного средства
ПО программно-аппаратного средства

Операционные системы и аппаратные платформы

Red Hat Inc. Red Hat Enterprise Linux 8
Red Hat Inc. Red Hat Enterprise Linux 9
Red Hat Inc. Red Hat Enterprise Linux 10
ООО «Ред Софт» РЕД ОС 8.0
Red Hat Inc. Red Hat Enterprise Linux AI 3

Уровень опасности уязвимости

Средний уровень опасности (базовая оценка CVSS 2.0 составляет 6,2)
Средний уровень опасности (базовая оценка CVSS 3.1 составляет 5,8)
Средний уровень опасности (оценка CVSS 4.0 составляет 5,3)

Возможные меры по устранению уязвимости

Использование рекомендаций:
Для pip:
https://sichard.ca/blog/2026/04/whats-new-in-pip-26.1/#fix-ace-caused-by-self-check-deferred-imports-cve-2026-6357
Для Ред ОС:
https://redos.red-soft.ru/search/?iblock_id=24&q=CVE-2026-6357
Для программных продуктов Red Hat Inc.:
https://access.redhat.com/security/cve/cve-2026-6357

Статус уязвимости

Подтверждена производителем

Наличие эксплойта

Данные уточняются

Информация об устранении

Уязвимость устранена

Идентификаторы других систем описаний уязвимостей

EPSS

Процентиль: 4%
0.00138
Низкий

5.8 Medium

CVSS3

6.2 Medium

CVSS2

Связанные уязвимости

ubuntu
3 месяца назад

pip prior to version 26.1 would run self-update check functionality after installing wheel files which required importing well-known Python modules names. These module imports were intentionally deferred to increase startup time of the pip CLI. The patch changes self-update functionality to run before wheels are installed to prevent newly-installed modules from being imported shortly after the installation of a wheel package. Users should still review package contents prior to installation.

CVSS3: 5.8
redhat
3 месяца назад

pip prior to version 26.1 would run self-update check functionality after installing wheel files which required importing well-known Python modules names. These module imports were intentionally deferred to increase startup time of the pip CLI. The patch changes self-update functionality to run before wheels are installed to prevent newly-installed modules from being imported shortly after the installation of a wheel package. Users should still review package contents prior to installation.

nvd
3 месяца назад

pip prior to version 26.1 would run self-update check functionality after installing wheel files which required importing well-known Python modules names. These module imports were intentionally deferred to increase startup time of the pip CLI. The patch changes self-update functionality to run before wheels are installed to prevent newly-installed modules from being imported shortly after the installation of a wheel package. Users should still review package contents prior to installation.

msrc
2 месяца назад

pip self-update functionality can import newly installed modules after wheel installation

debian
3 месяца назад

pip prior to version 26.1 would run self-update check functionality af ...

EPSS

Процентиль: 4%
0.00138
Низкий

5.8 Medium

CVSS3

6.2 Medium

CVSS2