{"id":"AZL-85265","summary":"CVE-2026-6357 affecting package python-virtualenv for versions less than 20.36.1-4","details":"pip prior to version 26.1 would run self-update check functionality after installing wheel files which required importing well-known Python modules names. These module imports were intentionally deferred to increase startup time of the pip CLI. The patch changes self-update functionality to run before wheels are installed to prevent newly-installed modules from being imported shortly after the installation of a wheel package. Users should still review package contents prior to installation.","modified":"2026-08-30T05:26:50Z","published":"2026-04-27T15:16:20Z","upstream":["CVE-2026-6357"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-6357"}],"affected":[{"package":{"name":"python-virtualenv","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/python-virtualenv"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"20.36.1-4"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-85265.json"}}],"schema_version":"1.9.0"}