Description
pip prior to version 26.1 would run self-update check functionality after installing wheel files which required importing well-known Python modules names. These module imports were intentionally deferred to increase startup time of the pip CLI. The patch changes self-update functionality to run before wheels are installed to prevent newly-installed modules from being imported shortly after the installation of a wheel package. Users should still review package contents prior to installation.
INFO
Published Date :
2026-04-27T14:19:47.657Z
Last Modified :
2026-04-27T22:17:49.582Z
Source :
PSF
AFFECTED PRODUCTS
The following products are affected by CVE-2026-6357 vulnerability.
| Vendors | Products |
|---|---|
| Pypa |
|
REFERENCES
Here, you will find a curated list of external links that provide in-depth information to CVE-2026-6357.
CVSS Vulnerability Scoring System
Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Attack Requirements
Privileges Required
User Interaction
VS Confidentiality
VS Integrity
VS Availability
SS Confidentiality
SS Integrity
SS Availability
Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact