Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-jp4c-xjxw-mgf9 | pip Vulnerable to Inclusion of Functionality from Untrusted Control Sphere |
Wed, 06 May 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-94 | |
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Tue, 28 Apr 2026 04:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Pypa
Pypa pip |
|
| Vendors & Products |
Pypa
Pypa pip |
Mon, 27 Apr 2026 23:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Mon, 27 Apr 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-829 | |
| Metrics |
ssvc
|
Mon, 27 Apr 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | pip prior to version 26.1 would run self-update check functionality after installing wheel files which required importing well-known Python modules names. These module imports were intentionally deferred to increase startup time of the pip CLI. The patch changes self-update functionality to run before wheels are installed to prevent newly-installed modules from being imported shortly after the installation of a wheel package. Users should still review package contents prior to installation. | |
| Title | pip self-update functionality can import newly installed modules after wheel installation | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: PSF
Published:
Updated: 2026-04-27T22:17:49.582Z
Reserved: 2026-04-15T13:55:02.734Z
Link: CVE-2026-6357
Updated: 2026-04-27T22:17:49.582Z
Status : Awaiting Analysis
Published: 2026-04-27T15:16:20.857
Modified: 2026-04-27T23:16:03.533
Link: CVE-2026-6357
OpenCVE Enrichment
Updated: 2026-05-06T02:00:12Z
Github GHSA