---
id: CVE-2026-6357
title: >-
  pip: pip: Arbitrary code execution or information disclosure via malicious
  wheel package installation (CVE-2026-6357)
summary: >-
  A flaw was found in pip. Prior to version 26.1, pip's self-update check
  functionality would execute after installing wheel packages. This process
  involved importing newly installed Python modules. A malicious actor could
  craft a specially …
severity: medium
cvss: 5.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:N'
cvssSource: vendor
cwe: CWE-94
vendor: Red Hat
product: Red Hat OpenShift AI (RHOAI)
affected:
  - exploit_intelligence
  - migration_toolkit_for_applications 8
  - migration_toolkit_for_virtualization
  - openshift_lightspeed
  - openshift_service_mesh 3
  - pen_drive_powered_by_red_hat_lightspeed
  - ai_inference_server
  - ansible_automation_platform 2
  - developer_hub
  - discovery 2
  - enterprise_linux 10
  - enterprise_linux 8
  - enterprise_linux 9
  - enterprise_linux_ai_rhel_ai 3
  - openshift_ai_rhoai
  - openshift_container_platform 4
  - openshift_dev_spaces
  - quay 3
  - satellite 6
  - trusted_artifact_signer
  - service_telemetry_framework 1.5
  - hardened_images
patched:
  - hardened_images
published: '2026-04-27'
updated: '2026-09-21'
sourceUpdated: '2026-09-21T11:43:38+00:00'
source: CSAF
sourceUrl: 'https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-6357.json'
references:
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-6357.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-6357'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2463234'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-6357'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-6357'
  - url: 'https://github.com/pypa/pip/pull/13923'
  - url: >-
      https://ichard26.github.io/blog/2026/04/whats-new-in-pip-26.1/#security-fixes
  - url: 'https://access.redhat.com/errata/RHSA-2026:48788'
  - url: >-
      https://github.com/pypa/pip/commit/b369bfc96cc524e00c267e1693290e6599c36bad
  - url: 'https://github.com/pypa/pip'
  - url: 'http://www.openwall.com/lists/oss-security/2026/04/27/7'
tags:
  - csaf
  - vex
  - red-hat
  - osv
  - pip
epss: 0.00171
epssPercentile: 0.05646
aliases:
  - GHSA-jp4c-xjxw-mgf9
  - PYSEC-2026-2876
ecosystem: pip
ingestedAt: '2026-07-13T18:58:00.020Z'
---

## Overview

A flaw was found in pip. Prior to version 26.1, pip's self-update check functionality would execute after installing wheel packages. This process involved importing newly installed Python modules. A malicious actor could craft a specially designed wheel package that, when installed, could lead to the execution of arbitrary code or information disclosure due to the premature import of its modules during the self-update check.

## Vendor advisories

- **RHSA-2026:48788** · Red Hat · fixed in: Red Hat Hardened Images · released 2026-07-30 · [advisory](https://access.redhat.com/errata/RHSA-2026:48788)
- **Red Hat VEX** · Moderate · affected: Exploit Intelligence, Migration Toolkit for Applications 8, Migration Toolkit for Virtualization, OpenShift Lightspeed, OpenShift Service Mesh 3, Pen Drive Powered by Red Hat Lightspeed, … · no fix planned: Exploit Intelligence, Migration Toolkit for Virtualization, Red Hat Ansible Automation Platform 2, Red Hat Enterprise Linux 10, … · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-6357.json)

**pip: pip: Arbitrary code execution or information disclosure via malicious wheel package installation** — rated Moderate by Red Hat. Released 2026-04-27, updated 2026-09-21.

Affected:

- Exploit Intelligence
- Migration Toolkit for Applications 8
- Migration Toolkit for Virtualization
- OpenShift Lightspeed
- OpenShift Service Mesh 3
- Pen Drive Powered by Red Hat Lightspeed
- Red Hat AI Inference Server
- Red Hat Ansible Automation Platform 2
- Red Hat Developer Hub
- Red Hat Discovery 2
- Red Hat Enterprise Linux 10
- Red Hat Enterprise Linux 8
- Red Hat Enterprise Linux 9
- Red Hat Enterprise Linux AI (RHEL AI) 3
- Red Hat OpenShift AI (RHOAI)
- Red Hat OpenShift Container Platform 4
- Red Hat OpenShift Dev Spaces
- Red Hat Quay 3
- Red Hat Satellite 6
- Red Hat Trusted Artifact Signer
- Service Telemetry Framework 1.5

Fixed:

- Red Hat Hardened Images

No fix planned:

- Exploit Intelligence
- Migration Toolkit for Virtualization
- Red Hat Ansible Automation Platform 2
- Red Hat Enterprise Linux 10
- Red Hat Enterprise Linux 9
- Red Hat Quay 3
- Red Hat Trusted Artifact Signer
- Migration Toolkit for Applications 8
- OpenShift Lightspeed
- OpenShift Service Mesh 3
- Pen Drive Powered by Red Hat Lightspeed
- Red Hat AI Inference Server
- Red Hat Developer Hub
- Red Hat Discovery 2
- Red Hat Enterprise Linux 8
- Red Hat Enterprise Linux AI (RHEL AI) 3
- Red Hat OpenShift AI (RHOAI)
- Red Hat OpenShift Container Platform 4
- Red Hat OpenShift Dev Spaces
- Red Hat Satellite 6
- Service Telemetry Framework 1.5

Not affected:

- Red Hat AI Inference Server
- Red Hat Ansible Automation Platform 2
- Red Hat Enterprise Linux AI (RHEL AI) 3
- Red Hat OpenShift AI (RHOAI)

## Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to:
https://images.redhat.com/ https://access.redhat.com/errata/RHSA-2026:48788

## Package advisory (CVE-2026-6357)

Affected packages:

- `pip < 26.1`

Patched in:

- `pip 26.1`

Source: https://osv.dev/vulnerability/GHSA-jp4c-xjxw-mgf9
