Home

Description

pip prior to version 26.1 would run self-update check functionality after installing wheel files which required importing well-known Python modules names. These module imports were intentionally deferred to increase startup time of the pip CLI. The patch changes self-update functionality to run before wheels are installed to prevent newly-installed modules from being imported shortly after the installation of a wheel package. Users should still review package contents prior to installation.

PUBLISHED Reserved 2026-04-15 | Published 2026-04-27 | Updated 2026-04-27 | Assigner PSF




MEDIUM: 5.3CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N

Product status

Default status
unaffected

Any version before 26.1
affected

Credits

Damian Shaw reporter

Damian Shaw remediation developer

Richard Si remediation reviewer

Seth Larson coordinator

References

www.openwall.com/lists/oss-security/2026/04/27/7

github.com/pypa/pip/pull/13923 patch

ichard26.github.io/blog/2026/04/whats-new-in-pip-26.1/ vendor-advisory

cve.org (CVE-2026-6357)

nvd.nist.gov (CVE-2026-6357)

Download JSON