PT-2026-35435 · Pypi · Pip
Damian Shaw
+2
·
Published
2026-04-27
·
Updated
2026-05-18
·
CVE-2026-6357
CVSS v3.1
5.8
Medium
| Vector | AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
pip versions prior to 26.1
Description
The self-update check functionality runs after installing wheel files, which requires importing well-known Python module names. These imports were deferred to improve the startup time of the pip CLI. This behavior allows newly installed modules to be imported shortly after the installation of a wheel package.
Recommendations
Update to version 26.1 or later.
Review package contents prior to installation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pip