{
  "document": {
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "distribution": {
      "text": "TuxCare License Agreement",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Cloud Linux Inc. and provide a link to the original.",
        "title": "Terms of Use"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://tuxcare.com/contact/",
      "name": "TuxCare",
      "namespace": "https://tuxcare.com/"
    },
    "references": [
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.tuxcare.com/csaf/v2/els_os/centos7els/vex/2026/cve-2026-6357-els_os-centos7els.json"
      }
    ],
    "tracking": {
      "current_release_date": "2026-09-16T16:55:25Z",
      "generator": {
        "date": "2026-09-16T16:55:25Z",
        "engine": {
          "name": "pyCSAF"
        }
      },
      "id": "CVE-2026-6357-ELS_OS-CENTOS7ELS",
      "initial_release_date": "2026-04-27T15:16:00Z",
      "revision_history": [
        {
          "date": "2026-04-27T15:16:00Z",
          "number": "1",
          "summary": "Initial version"
        },
        {
          "date": "2026-09-16T13:17:46Z",
          "number": "2",
          "summary": "Official Publication"
        },
        {
          "date": "2026-09-16T16:55:25Z",
          "number": "3",
          "summary": "Update document"
        }
      ],
      "status": "final",
      "version": "3"
    },
    "title": "Security update on CVE-2026-6357"
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Community Enterprise Operating System 7",
                "product": {
                  "name": "Community Enterprise Operating System 7",
                  "product_id": "CentOS-7",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:o:centos:centos:7:*:*:*:*:*:*:*"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Community Enterprise Operating System"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "python3-pip-0:9.0.3-8.0.3.el7.noarch",
                "product": {
                  "name": "python3-pip-0:9.0.3-8.0.3.el7.noarch",
                  "product_id": "python3-pip-0:9.0.3-8.0.3.el7.noarch",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/centos/python3-pip@9.0.3-8.0.3.el7?arch=noarch"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "python3-pip-0:9.0.3-8.el7.noarch",
                "product": {
                  "name": "python3-pip-0:9.0.3-8.el7.noarch",
                  "product_id": "python3-pip-0:9.0.3-8.el7.noarch",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/centos/python3-pip@9.0.3-8.el7?arch=noarch"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "noarch"
          }
        ],
        "category": "vendor",
        "name": "Red Hat, Inc."
      },
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version",
                "name": "python3-pip-0:9.0.3-8.0.3.el7.tuxcare.els1.noarch",
                "product": {
                  "name": "python3-pip-0:9.0.3-8.0.3.el7.tuxcare.els1.noarch",
                  "product_id": "python3-pip-0:9.0.3-8.0.3.el7.tuxcare.els1.noarch",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/python3-pip@9.0.3-8.0.3.el7.tuxcare.els1?arch=noarch"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "python3-pip-0:9.0.3-8.el7.tuxcare.els1.noarch",
                "product": {
                  "name": "python3-pip-0:9.0.3-8.el7.tuxcare.els1.noarch",
                  "product_id": "python3-pip-0:9.0.3-8.el7.tuxcare.els1.noarch",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/python3-pip@9.0.3-8.el7.tuxcare.els1?arch=noarch"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "python3-pip-0:9.0.3-8.el7.tuxcare.els2.noarch",
                "product": {
                  "name": "python3-pip-0:9.0.3-8.el7.tuxcare.els2.noarch",
                  "product_id": "python3-pip-0:9.0.3-8.el7.tuxcare.els2.noarch",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/python3-pip@9.0.3-8.el7.tuxcare.els2?arch=noarch"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "noarch"
          }
        ],
        "category": "vendor",
        "name": "TuxCare"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "python3-pip-0:9.0.3-8.0.3.el7.tuxcare.els1.noarch as a component of Community Enterprise Operating System 7",
          "product_id": "CentOS-7:python3-pip-0:9.0.3-8.0.3.el7.tuxcare.els1.noarch"
        },
        "product_reference": "python3-pip-0:9.0.3-8.0.3.el7.tuxcare.els1.noarch",
        "relates_to_product_reference": "CentOS-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "python3-pip-0:9.0.3-8.el7.tuxcare.els1.noarch as a component of Community Enterprise Operating System 7",
          "product_id": "CentOS-7:python3-pip-0:9.0.3-8.el7.tuxcare.els1.noarch"
        },
        "product_reference": "python3-pip-0:9.0.3-8.el7.tuxcare.els1.noarch",
        "relates_to_product_reference": "CentOS-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "python3-pip-0:9.0.3-8.el7.tuxcare.els2.noarch as a component of Community Enterprise Operating System 7",
          "product_id": "CentOS-7:python3-pip-0:9.0.3-8.el7.tuxcare.els2.noarch"
        },
        "product_reference": "python3-pip-0:9.0.3-8.el7.tuxcare.els2.noarch",
        "relates_to_product_reference": "CentOS-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "python3-pip-0:9.0.3-8.0.3.el7.noarch as a component of Community Enterprise Operating System 7",
          "product_id": "CentOS-7:python3-pip-0:9.0.3-8.0.3.el7.noarch"
        },
        "product_reference": "python3-pip-0:9.0.3-8.0.3.el7.noarch",
        "relates_to_product_reference": "CentOS-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "python3-pip-0:9.0.3-8.el7.noarch as a component of Community Enterprise Operating System 7",
          "product_id": "CentOS-7:python3-pip-0:9.0.3-8.el7.noarch"
        },
        "product_reference": "python3-pip-0:9.0.3-8.el7.noarch",
        "relates_to_product_reference": "CentOS-7"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2026-6357",
      "cwe": {
        "id": "CWE-829",
        "name": "Inclusion of Functionality from Untrusted Control Sphere"
      },
      "notes": [
        {
          "category": "description",
          "text": "pip prior to version 26.1 would run self-update check functionality after installing wheel files which required importing well-known Python modules names. These module imports were intentionally deferred to increase startup time of the pip CLI. The patch changes self-update functionality to run before wheels are installed to prevent newly-installed modules from being imported shortly after the installation of a wheel package. Users should still review package contents prior to installation.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "known_affected": [
          "CentOS-7:python3-pip-0:9.0.3-8.0.3.el7.noarch",
          "CentOS-7:python3-pip-0:9.0.3-8.0.3.el7.tuxcare.els1.noarch",
          "CentOS-7:python3-pip-0:9.0.3-8.el7.noarch",
          "CentOS-7:python3-pip-0:9.0.3-8.el7.tuxcare.els1.noarch",
          "CentOS-7:python3-pip-0:9.0.3-8.el7.tuxcare.els2.noarch"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2026-6357"
        },
        {
          "category": "external",
          "summary": "https://github.com/pypa/pip/pull/13923",
          "url": "https://github.com/pypa/pip/pull/13923"
        },
        {
          "category": "external",
          "summary": "https://ichard26.github.io/blog/2026/04/whats-new-in-pip-26.1/#security-fixes",
          "url": "https://ichard26.github.io/blog/2026/04/whats-new-in-pip-26.1/#security-fixes"
        },
        {
          "category": "external",
          "summary": "http://www.openwall.com/lists/oss-security/2026/04/27/7",
          "url": "http://www.openwall.com/lists/oss-security/2026/04/27/7"
        }
      ],
      "release_date": "2026-04-27T15:16:00Z",
      "remediations": [
        {
          "category": "no_fix_planned",
          "date": "2026-09-16T14:51:32.625309Z",
          "details": "This is a local-only pip CLI issue: before 26.1 the version-check ran after a wheel install and could import a just-installed module, but exploitation requires a high‑privilege user to actively run pip and to have installed a specially crafted/malicious wheel that deliberately collides with the module names pip imports. With no remote attack surface, required user interaction, and impact limited to the transient installer path rather than any long‑running service, it presents low practical risk in centrally managed enterprise VMs/servers and can be safely deprioritized.",
          "product_ids": [
            "CentOS-7:python3-pip-0:9.0.3-8.0.3.el7.noarch",
            "CentOS-7:python3-pip-0:9.0.3-8.0.3.el7.tuxcare.els1.noarch",
            "CentOS-7:python3-pip-0:9.0.3-8.el7.noarch",
            "CentOS-7:python3-pip-0:9.0.3-8.el7.tuxcare.els1.noarch",
            "CentOS-7:python3-pip-0:9.0.3-8.el7.tuxcare.els2.noarch"
          ]
        }
      ]
    }
  ]
}