cbcvebase.
CVE-2026-6357
published 2026-04-27

CVE-2026-6357: pip prior to version 26.1 would run self-update check functionality after installing wheel files which required importing well-known Python modules names…

medium5.3CVSS 4.0
AVLACLATPPRHUIAVCHVIHVANSCNSINSANEXCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
pip prior to version 26.1 would run self-update check functionality after installing wheel files which required importing well-known Python modules names. These module imports were intentionally deferred to increase startup time of the pip CLI. The patch changes self-update functionality to run before wheels are installed to prevent newly-installed modules from being imported shortly after the installation of a wheel package. Users should still review package contents prior to installation.

Affected

114 ranges· showing 25
VendorProductVersion rangeFixed in
ansible-automation-platform-24controller-rhel8
ansible-automation-platform-25controller-rhel8
ansible-automation-platform-26controller-rhel9
ansible-automation-platform-26controller-rhel9-operator
ansible-automation-platform-26de-minimal-rhel9
ansible-automation-platform-26de-supported-rhel9
ansible-automation-platform-26eda-controller-rhel9-operator
ansible-automation-platform-26gateway-rhel9
ansible-automation-platform-26gateway-rhel9-operator
ansible-automation-platform-26hub-rhel9-operator
ansible-automation-platform-26lightspeed-rhel9-operator
ansible-automation-platform-26platform-resource-rhel9-operator
ansible-automation-platform-tech-previewmetrics-service-rhel9
ansible-automation-platform-tech-previewmetrics-service-rhel9-operator
ansible-automation-platformautomation-dashboard-rhel9
devspacesudi-rhel9
discoverydiscovery-server-rhel9
exploit-intelligence-tech-previewvulnerability-analysis-rhel9
migration-toolkit-virtualizationmtv-rhel9-operator
mtamta-rhel9-operator
mtv-candidatemtv-rhel9-operator
openshift-lightspeedlightspeed-service-api-rhel9
openshift-service-meshkiali-rhel9-operator
openshift4ose-ansible-rhel9-operator
pen-drivepen-drive-scanner-rhel9