CVE-2022-40897

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
23/12/2022
Last modified:
04/11/2025

Description

Python Packaging Authority (PyPA) setuptools before 65.5.1 allows remote attackers to cause a denial of service via HTML in a crafted package or custom PackageIndex page. There is a Regular Expression Denial of Service (ReDoS) in package_index.py.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:python:setuptools:*:*:*:*:*:*:*:* 65.5.1 (excluding)


References to Advisories, Solutions, and Tools