Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jp4c-xjxw-mgf9

Опубликовано: 27 апр. 2026
Источник: github
Github: Прошло ревью
CVSS4: 5.3

Описание

pip Vulnerable to Inclusion of Functionality from Untrusted Control Sphere

pip prior to version 26.1 would run self-update check functionality after installing wheel files which required importing well-known Python modules names. These module imports were intentionally deferred to increase startup time of the pip CLI. The patch changes self-update functionality to run before wheels are installed to prevent newly-installed modules from being imported shortly after the installation of a wheel package. Users should still review package contents prior to installation.

Пакеты

Наименование

pip

pip
Затронутые версииВерсия исправления

< 26.1

26.1

EPSS

Процентиль: 4%
0.00138
Низкий

5.3 Medium

CVSS4

Дефекты

CWE-829

Связанные уязвимости

ubuntu
3 месяца назад

pip prior to version 26.1 would run self-update check functionality after installing wheel files which required importing well-known Python modules names. These module imports were intentionally deferred to increase startup time of the pip CLI. The patch changes self-update functionality to run before wheels are installed to prevent newly-installed modules from being imported shortly after the installation of a wheel package. Users should still review package contents prior to installation.

CVSS3: 5.8
redhat
3 месяца назад

pip prior to version 26.1 would run self-update check functionality after installing wheel files which required importing well-known Python modules names. These module imports were intentionally deferred to increase startup time of the pip CLI. The patch changes self-update functionality to run before wheels are installed to prevent newly-installed modules from being imported shortly after the installation of a wheel package. Users should still review package contents prior to installation.

nvd
3 месяца назад

pip prior to version 26.1 would run self-update check functionality after installing wheel files which required importing well-known Python modules names. These module imports were intentionally deferred to increase startup time of the pip CLI. The patch changes self-update functionality to run before wheels are installed to prevent newly-installed modules from being imported shortly after the installation of a wheel package. Users should still review package contents prior to installation.

msrc
3 месяца назад

pip self-update functionality can import newly installed modules after wheel installation

debian
3 месяца назад

pip prior to version 26.1 would run self-update check functionality af ...

EPSS

Процентиль: 4%
0.00138
Низкий

5.3 Medium

CVSS4

Дефекты

CWE-829