View all vulnerabilities

CVE-2022-40897

Python Packaging Authority (PyPA) setuptools before 65.5.1 allows remote attackers to cause a denial of service via HTML in a crafted package or custom PackageIndex page. There is a Regular Expression Denial of Service (ReDoS) in package_index.py.

Patch Available

Fix available through Seal Security. No upgrade required, protect your application instantly.

Fix without upgrading
Vulnerability Details
Score
Score Vector
Affected Versions
setuptools < 43a9c9bfa6aa626ec2a22540bea28d2ca77964be; setuptools < 65.5.1
Severity
Ecosystem
Python
Publish Date
December 22, 2022
Modified Date
December 5, 2023