PT-2026-35435 · Pypi+1 · Pip+1

·

CVE-2026-6357

·

Published

2026-04-27

·

Updated

2026-07-21

CVSS v2.0

6.2

Medium

VectorAV:L/AC:L/Au:S/C:C/I:C/A:N
Name of the Vulnerable Software and Affected Versions pip versions prior to 26.1
Description The self-update check functionality runs after installing wheel files, which requires importing well-known Python module names. These imports were deferred to improve the startup time of the pip CLI. This behavior allows newly installed modules to be imported shortly after the installation of a wheel package.
Recommendations Update to version 26.1 or later. Review package contents prior to installation.

Exploit

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-09786
CLEANSTART-2026-DD95169
CLEANSTART-2026-HZ86045
CLEANSTART-2026-KY55512
CLEANSTART-2026-NN42198
CLEANSTART-2026-NR60332
CLEANSTART-2026-QK55639
CLEANSTART-2026-SA70432
CLEANSTART-2026-SY44974
CLEANSTART-2026-UC45646
CLEANSTART-2026-YC81398
CLEANSTART-2026-ZI38454
CLEANSTART-2026-ZO99127
CVE-2026-6357
ECHO-0A2A-4462-0B2A
GHSA-JP4C-XJXW-MGF9
OPENSUSE-SU-2026:20880-1
PYSEC-2026-2876
SUSE-SU-2026:22018-1
SUSE-SU-2026:2387-1
SUSE-SU-2026:2634-1
SUSE-SU-2026:2664-1
SUSE-SU-2026:2758-1

Affected Products

Red Os
Pip