CVE-2026-6357
MediumAdvisory
Published 27 Apr 2026In the index since 5 Sept 2026
- Severity
- Medium
- worst across findings
- CVSS
- 5.3
- base score, highest
- EPSS
- 0.001
- 4th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 1,271
- of 17,787 indexed, latest versions
- Container images
- 1,222
- deployed by those charts
- Fix available
- 2 of 3
- affected packages
pip Vulnerable to Inclusion of Functionality from Untrusted Control Sphere
Carried by container images the latest versions of 1,271 of 17,787 indexed charts deploy, on 1,222 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| pippypi | 1.5.4, 8.1.1, 8.1.2, 9.0.0+65 more | 26.1 | 1,214 |
| python-pipdeb | 1.5.4-1ubuntu4, 8.1.1-2ubuntu0.4, 9.0.1-2.3~ubuntu1, 9.0.1-2.3~ubuntu1.18.04.1+25 more | no fix listed | 141 |
| py3-pipapk | 25.0.1-r0, 25.2-r0, 25.3-r2, 25.3-r3+2 more | 26.1.1-r0 | 9 |
- OSV records
- CGA-62q8-238c-v33cCGA-6934-j8w5-ggwcCGA-8w3m-p9rg-vfgvDEBIAN-CVE-2026-6357GHSA-jp4c-xjxw-mgf9UBUNTU-CVE-2026-6357
- Also known as
- CGA-65q2-63cw-4355, CGA-69j4-wp86-cj67, CGA-74h5-68pc-h963, CGA-7pw2-rhmg-m2hr, CGA-7vq8-m28w-6rmf, CGA-qmmj-2pmg-2vpx, CGA-r482-24m8-gv9h, CGA-vqpj-m7r7-vf4j, CGA-w8wp-q9p5-56fw, PYSEC-2026-2876
Charts affected
1,271 by stars
Container images carrying it
1,222 by charts deploying them
A fixed version is listed for 2 of the 3 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| amagdi888/ | d8a10fc8faf6 | pip | 26.1 | 1 |
| amancevice/ | c8c04bfe3d66 | pip | 26.1 | 1 |
| amd64/ | e20a653e0f51 | pip | 26.1 | 1 |
| amundsendev/ | 69e7915e61c1 | pip | 26.1 | 1 |
| amundsendev/ | 4d98eb21f5f9 | pip | 26.1 | 1 |
| amundsendev/ | 99dda9502c3e | pip | 26.1 | 1 |
| anchore/ | bde9eedf639d | pip | 26.1 | 1 |
| anchore/ | ed9b3badd17c | pip | 26.1 | 1 |
| andrewgolikov55/ | fcc001b61c0e | pip python-pip | 26.1 no fix listed | 1 |
| andreymileshin/ | f7b300bc9e66 | pip | 26.1 | 1 |
| andreymileshin/ | e0825acc9e48 | pip | 26.1 | 1 |
| apache/ | 64e58748b6b9 | pip | 26.1 | 1 |
| apache/ | ce90bdc3d2af | pip | 26.1 | 1 |
| apache/ | e5560ad0b86e | pip | 26.1 | 1 |
| apache/ | a7d9970c148f | pip | 26.1 | 1 |
| apache/ | af361b20bec0 | pip | 26.1 | 1 |
| apachepulsar/ | 16f9fdab3fa6 | pip python-pip | 26.1 no fix listed | 1 |
| apachepulsar/ | 3b262ab7a7d9 | pip python-pip | 26.1 no fix listed | 1 |
| apachepulsar/ | 4db6ff0b4045 | pip | 26.1 | 1 |
| apachepulsar/ | 9c9947de139d | pip python-pip | 26.1 no fix listed | 1 |
| apachepulsar/ | d056c89b7131 | pip | 26.1 | 1 |
| apachepulsar/ | d538416d5afe | pip | 26.1 | 1 |
| apache/ | 76c176e8a0e4 | pip python-pip | 26.1 no fix listed | 1 |
| apache/ | 975ab033580d | pip | 26.1 | 1 |
| apache/ | ab9467fd712c | pip | 26.1 | 1 |
| apecloud/ | 8ac9947a2c84 | pip | 26.1 | 1 |
| apsl/ | 51e2de5c2c70 | pip | 26.1 | 1 |
| aquasec/ | 0bf607ce9308 | pip | 26.1 | 1 |
| archish27/ | 6610071a2101 | pip | 26.1 | 1 |
| archivebox/ | 1a5a37331091 | pip | 26.1 | 1 |
| arconixforge/ | c08d7c438966 | pip | 26.1 | 1 |
| aristidetm/ | 469dbc951224 | pip | 26.1 | 1 |
| aristidetm/ | ccb516cb8474 | pip | 26.1 | 1 |
| arthurjguerra18/ | f540af20b307 | pip | 26.1 | 1 |
| arunvelsriram/ | 655ad18fd8d6 | pip python-pip | 26.1 no fix listed | 1 |
| asdkant/ | a23d8bf7c885 | pip | 26.1 | 1 |
| assistiot/ | c3adbab6a3e7 | pip | 26.1 | 1 |
| assistiot/ | 0aacefac9677 | pip | 26.1 | 1 |
| assistiot/ | 0518b63a2e69 | pip | 26.1 | 1 |
| assistiot/ | 0fce3ea719a5 | pip | 26.1 | 1 |
| assistiot/ | 792715dd3084 | pip | 26.1 | 1 |
| assistiot/ | 0df4b4fa899a | pip | 26.1 | 1 |
| assistiot/ | 30812ba93555 | pip python-pip | 26.1 no fix listed | 1 |
| assistiot/ | 44a37b00d4f8 | pip | 26.1 | 1 |
| assistiot/ | a942dc14030a | pip | 26.1 | 1 |
| assistiot/ | 8b5d118bdf0e | pip | 26.1 | 1 |
| assistiot/ | 7d6a0d534c7f | pip | 26.1 | 1 |
| assistiot/ | 38b003e55ff3 | pip | 26.1 | 1 |
| assistiot/ | b1dbe4d62a03 | pip python-pip | 26.1 no fix listed | 1 |
| assistiot/ | e32b87786142 | pip | 26.1 | 1 |