Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-6357

Опубликовано: 27 апр. 2026
Источник: nvd
EPSS Низкий

Описание

pip prior to version 26.1 would run self-update check functionality after installing wheel files which required importing well-known Python modules names. These module imports were intentionally deferred to increase startup time of the pip CLI. The patch changes self-update functionality to run before wheels are installed to prevent newly-installed modules from being imported shortly after the installation of a wheel package. Users should still review package contents prior to installation.

EPSS

Процентиль: 4%
0.00138
Низкий

Дефекты

CWE-829

Связанные уязвимости

ubuntu
3 месяца назад

pip prior to version 26.1 would run self-update check functionality after installing wheel files which required importing well-known Python modules names. These module imports were intentionally deferred to increase startup time of the pip CLI. The patch changes self-update functionality to run before wheels are installed to prevent newly-installed modules from being imported shortly after the installation of a wheel package. Users should still review package contents prior to installation.

CVSS3: 5.8
redhat
3 месяца назад

pip prior to version 26.1 would run self-update check functionality after installing wheel files which required importing well-known Python modules names. These module imports were intentionally deferred to increase startup time of the pip CLI. The patch changes self-update functionality to run before wheels are installed to prevent newly-installed modules from being imported shortly after the installation of a wheel package. Users should still review package contents prior to installation.

msrc
3 месяца назад

pip self-update functionality can import newly installed modules after wheel installation

debian
3 месяца назад

pip prior to version 26.1 would run self-update check functionality af ...

github
3 месяца назад

pip Vulnerable to Inclusion of Functionality from Untrusted Control Sphere

EPSS

Процентиль: 4%
0.00138
Низкий

Дефекты

CWE-829