CVE-2026-6357
ADVISORY - githubSummary
pip prior to version 26.1 would run self-update check functionality after installing wheel files which required importing well-known Python modules names. These module imports were intentionally deferred to increase startup time of the pip CLI. The patch changes self-update functionality to run before wheels are installed to prevent newly-installed modules from being imported shortly after the installation of a wheel package. Users should still review package contents prior to installation.
Common Weakness Enumeration (CWE)
Inclusion of Functionality from Untrusted Control Sphere
Inclusion of Functionality from Untrusted Control Sphere
NIST
-
CVSS SCORE
5.3mediumGitHub
-
CVSS SCORE
5.3mediumDebian
-
Ubuntu
-
CVSS SCORE
N/AmediumAmazon
-
CVSS SCORE
N/AhighAmazon
-
CVSS SCORE
N/AhighAmazon
-
CVSS SCORE
N/AhighAmazon
-
CVSS SCORE
N/AhighAmazon
-
CVSS SCORE
N/AhighAmazon
-
CVSS SCORE
N/AhighChainguard
CGA-p852-vq7j-f496
-
Photon
CVE-2026-6357
-
CVSS SCORE
5.6mediumminimos
MINI-4hq9-rm2j-67f4
-
minimos
MINI-4mv4-xw4q-9v7m
-
minimos
MINI-6vpf-gp4x-w56q
-
minimos
MINI-834f-55f7-x32g
-
minimos
MINI-83jr-f9qp-7vm5
-
minimos
MINI-crx3-vx3p-2mfx
-
minimos
MINI-gx8f-ffch-hwf8
-
minimos
MINI-v92g-j3vg-2jfp
-