CVE-2022-40897

Updated: 2025-11-10 02:53:53.62691

Description:

Python Packaging Authority (PyPA) setuptools before 65.5.1 allows remote attackers to cause a denial of service via HTML in a crafted package or custom PackageIndex page. There is a Regular Expression Denial of Service (ReDoS) in package_index.py.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x 0.0
CVSS Version 3.x MEDIUM 5.9

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

CentOS 7 ELS python3-setuptools 39.2.0 5.9 MEDIUM Released CLSA-2025:1761056282 2025-11-03 17:11:29
CentOS 8.4 ELS python3 3.6.8 5.9 MEDIUM Not Vulnerable 2025-02-20 06:37:51
CentOS 8.4 ELS python2 2.7.18 5.9 MEDIUM Not Vulnerable 2025-02-20 11:32:32
CentOS 8.5 ELS python2 2.7.18 5.9 MEDIUM Not Vulnerable 2025-02-20 11:32:31
CentOS 8.5 ELS python3 3.6.8 5.9 MEDIUM Not Vulnerable 2025-02-20 06:37:51
Oracle Linux 7 ELS python3-setuptools 39.2.0 5.9 MEDIUM Released CLSA-2025:1761051864 2025-10-21 18:47:42
Ubuntu 16.04 ELS python2.7 2.7.12 5.9 MEDIUM Not Vulnerable 2025-02-20 11:32:31
Ubuntu 18.04 ELS python2.7 2.7.17-1 5.9 MEDIUM Not Vulnerable 2025-02-20 11:32:31