PT-2026-35435 · Pypi · Pip

Damian Shaw

+2

·

Published

2026-04-27

·

Updated

2026-05-18

·

CVE-2026-6357

CVSS v3.1

5.8

Medium

VectorAV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions pip versions prior to 26.1
Description The self-update check functionality runs after installing wheel files, which requires importing well-known Python module names. These imports were deferred to improve the startup time of the pip CLI. This behavior allows newly installed modules to be imported shortly after the installation of a wheel package.
Recommendations Update to version 26.1 or later. Review package contents prior to installation.

Fix

Weakness Enumeration

Related Identifiers

CLEANSTART-2026-HZ86045
CLEANSTART-2026-QK55639
CLEANSTART-2026-SY44974
CVE-2026-6357
ECHO-0A2A-4462-0B2A
GHSA-JP4C-XJXW-MGF9

Affected Products

Pip