https://seclists.org/oss-sec/2026/q2/234: [oss-security][CVE-2026-6357] pip self-update functionality can import newly installed modules after wheel installation
Published Apr 27, 2026
·Updated
Affected Software
1 affected component
pypi/pip
Frequently Asked Questions
1
What is the severity of CVE-2026-6357?
CVE-2026-6357 has been classified as a MEDIUM severity vulnerability.
2
How do I fix CVE-2026-6357?
To fix CVE-2026-6357, ensure you are using the latest version of pip where the vulnerability has been patched.
3
What impact does CVE-2026-6357 have on pip users?
The impact of CVE-2026-6357 allows for the potential importation of newly installed modules after wheel installation, which could lead to unintended behavior.
4
Is CVE-2026-6357 a widespread issue?
CVE-2026-6357 specifically affects users of the pip project, particularly those who utilize the self-update functionality.
5
When was CVE-2026-6357 published?
CVE-2026-6357 was published on April 27, 2026.