Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-6357

Опубликовано: 27 апр. 2026
Источник: redhat
CVSS3: 5.8
EPSS Низкий

Описание

pip prior to version 26.1 would run self-update check functionality after installing wheel files which required importing well-known Python modules names. These module imports were intentionally deferred to increase startup time of the pip CLI. The patch changes self-update functionality to run before wheels are installed to prevent newly-installed modules from being imported shortly after the installation of a wheel package. Users should still review package contents prior to installation.

A flaw was found in pip. Prior to version 26.1, pip's self-update check functionality would execute after installing wheel packages. This process involved importing newly installed Python modules. A malicious actor could craft a specially designed wheel package that, when installed, could lead to the execution of arbitrary code or information disclosure due to the premature import of its modules during the self-update check.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Exploit Intelligenceexploit-intelligence-tech-preview/vulnerability-analysis-rhel9Out of support scope
Migration Toolkit for Applications 8mta/mta-rhel9-operatorFix deferred
Migration Toolkit for Virtualizationmigration-toolkit-virtualization/mtv-rhel9-operatorFix deferred
Migration Toolkit for Virtualizationmtv-candidate/mtv-rhel9-operatorOut of support scope
OpenShift Lightspeedopenshift-lightspeed/lightspeed-service-api-rhel9Fix deferred
OpenShift Service Mesh 3openshift-service-mesh/kiali-rhel9-operatorFix deferred
Pen Drive Powered by Red Hat Lightspeedpen-drive/pen-drive-scanner-rhel9Fix deferred
Red Hat AI Inference Serverrhaiis/model-opt-cuda-rhel9Not affected
Red Hat AI Inference Serverrhaiis/vllm-cpu-rhel9Not affected
Red Hat AI Inference Serverrhaiis/vllm-cuda-rhel9Not affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-94
https://bugzilla.redhat.com/show_bug.cgi?id=2463234pip: pip: Arbitrary code execution or information disclosure via malicious wheel package installation

EPSS

Процентиль: 4%
0.00138
Низкий

5.8 Medium

CVSS3

Связанные уязвимости

ubuntu
3 месяца назад

pip prior to version 26.1 would run self-update check functionality after installing wheel files which required importing well-known Python modules names. These module imports were intentionally deferred to increase startup time of the pip CLI. The patch changes self-update functionality to run before wheels are installed to prevent newly-installed modules from being imported shortly after the installation of a wheel package. Users should still review package contents prior to installation.

nvd
3 месяца назад

pip prior to version 26.1 would run self-update check functionality after installing wheel files which required importing well-known Python modules names. These module imports were intentionally deferred to increase startup time of the pip CLI. The patch changes self-update functionality to run before wheels are installed to prevent newly-installed modules from being imported shortly after the installation of a wheel package. Users should still review package contents prior to installation.

msrc
3 месяца назад

pip self-update functionality can import newly installed modules after wheel installation

debian
3 месяца назад

pip prior to version 26.1 would run self-update check functionality af ...

github
3 месяца назад

pip Vulnerable to Inclusion of Functionality from Untrusted Control Sphere

EPSS

Процентиль: 4%
0.00138
Низкий

5.8 Medium

CVSS3