CVE-2026-6357

EUVD-2026-25857
pip prior to version 26.1 would run self-update check functionality after installing wheel files which required importing well-known Python modules names. These module imports were intentionally deferred to increase startup time of the pip CLI. The patch changes self-update functionality to run before wheels are installed to prevent newly-installed modules from being imported shortly after the installation of a wheel package. Users should still review package contents prior to installation.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
UNKNOWN
---
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: 4%
Debian logo
Debian Releases
Debian Product
Codename
python-pip
bookworm
no-dsa
bullseye
postponed
bullseye (security)
vulnerable
forky
26.1.2+dfsg-1
fixed
sid
26.1.2+dfsg-1
fixed
trixie
no-dsa
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
python-pip-wheel
Amazon Linux 2
0:20.2.2-1.amzn2.0.17
fixed
python2-pip
Amazon Linux 2
0:20.2.2-1.amzn2.0.17
fixed
python3-pip
Amazon Linux 2
0:20.2.2-1.amzn2.0.17
fixed
Amazon Linux 2023
0:21.3.1-2.amzn2023.0.19
fixed
python3-pip-wheel
Amazon Linux 2023
0:21.3.1-2.amzn2023.0.19
fixed
python3.11-pip
Amazon Linux 2023
0:22.3.1-2.amzn2023.0.12
fixed
python3.11-pip-wheel
Amazon Linux 2023
0:22.3.1-2.amzn2023.0.12
fixed
python3.12-pip
Amazon Linux 2023
0:23.2.1-4.amzn2023.0.9
fixed
python3.12-pip-wheel
Amazon Linux 2023
0:23.2.1-4.amzn2023.0.9
fixed
python3.13-pip
Amazon Linux 2023
0:24.2-259.amzn2023.0.5
fixed
python3.13-pip-wheel
Amazon Linux 2023
0:24.2-259.amzn2023.0.5
fixed
python3.14-pip
Amazon Linux 2023
0:25.1.1-1.amzn2023.0.2
fixed
python3.14-pip-wheel
Amazon Linux 2023
0:25.1.1-1.amzn2023.0.2
fixed
Azure Linux logo
Azure Linux Releases
Azure Package
Release
python-pip
Azure Linux 3.0
0:24.2-8.azl3
fixed
python-virtualenv
Azure Linux 3.0
0:20.36.1-4.azl3
fixed