Logo
vulnerabilityCVE-2026-6357
Name
CVE-2026-6357
Source
NVD ( link)Debian ( link)
Description
pip prior to version 26.1 would run self-update check functionality after installing wheel files which required importing well-known Python modules names. These module imports were intentionally deferred to increase startup time of the pip CLI. The patch changes self-update functionality to run before wheels are installed to prevent newly-installed modules from being imported shortly after the installation of a wheel package. Users should still review package contents prior to installation.
Published Date
Updated Date
Workaround
-
Advisories

Analysis#


Affected Component
Analysis
python-pip
Exploitable

Vulnerability Ratings#


5.3
CVSSv4
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
master
26.1
Not Affected
openwrt
master
26.2.1-r1
Not Affected
openwrt
openwrt-25.12
23.3.1-r2
Exploitable
yocto
master
26.2
Not Affected