PT-2026-35435 · Pypi+1 · Pip+1
CVSS v2.0
6.2
Medium
| Vector | AV:L/AC:L/Au:S/C:C/I:C/A:N |
Name of the Vulnerable Software and Affected Versions
pip versions prior to 26.1
Description
The self-update check functionality runs after installing wheel files, which requires importing well-known Python module names. These imports were deferred to improve the startup time of the pip CLI. This behavior allows newly installed modules to be imported shortly after the installation of a wheel package.
Recommendations
Update to version 26.1 or later.
Review package contents prior to installation.
Exploit
Fix
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Red Os
Pip