PT-2022-6567 · Python Packaging Authority+10 · Setuptools+10

Jaraco

·

Published

2022-11-16

·

Updated

2026-05-04

·

CVE-2022-40897

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:L/SI:L/SA:N
Name of the Vulnerable Software and Affected Versions Python Packaging Authority (PyPA) setuptools versions 65.3.0 through 65.5.0
Description The issue is related to insufficient input validation when processing HTML content, allowing remote attackers to cause a denial of service via crafted HTML in a package or custom PackageIndex page. This is due to a Regular Expression Denial of Service (ReDoS) in package index.py. The vulnerability can be exploited by sending specially crafted data to the application, resulting in a denial of service attack.
Recommendations For versions 65.3.0 through 65.5.0, update to version 65.5.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the package index module to minimize the risk of exploitation. Avoid using the vulnerable Regular Expression in the package index.py file until the issue is resolved.

Exploit

Fix

DoS

Weakness Enumeration

Related Identifiers

ALSA-2023:0835
ALSA-2023:0952
ALSA-2024:2985
ALSA-2024:2987
ALT-PU-2022-3087
ALT-PU-2024-15879
ALT-PU-2024-15964
AZL-60207
BDU:2023-02445
BIT-SETUPTOOLS-2022-40897
CESA-2023_0835
CESA-2024_2985
CESA-2024_2987
CVE-2022-40897
DLA-3876-1
ECHO-3699-2FC9-324A
GHSA-R9HX-VWMV-Q579
INFSA-2024_2985
INFSA-2024_2987
MGASA-2023-0219
OESA-2023-1004
OPENSUSE-SU-2023_0091-1
OPENSUSE-SU-2023_0159-1
OPENSUSE-SU-2023_0202-1
OPENSUSE-SU-2023_4517-1
PYSEC-2022-43012
RHSA-2023:0835
RHSA-2023:0952
RHSA-2023:6793
RHSA-2023:7395
RHSA-2023_0835
RHSA-2023_0952
RHSA-2024:2985
RHSA-2024:2987
RHSA-2024:4421
RHSA-2024:6915
RHSA-2024_2985
RHSA-2024_2987
RLSA-2023:0835
RLSA-2023:0952
RLSA-2024:2985
SUSE-SU-2023:0091-1
SUSE-SU-2023:0093-1
SUSE-SU-2023:0094-1
SUSE-SU-2023:0159-1
SUSE-SU-2023:0202-1
SUSE-SU-2023:0223-1
SUSE-SU-2023:0402-1
SUSE-SU-2023:0403-1
SUSE-SU-2023:4517-1
SUSE-SU-2023_0091-1
SUSE-SU-2023_0093-1
SUSE-SU-2023_0094-1
SUSE-SU-2023_0159-1
SUSE-SU-2023_4517-1
SUSE-SU-2024:2435-1
USN-5817-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu
Setuptools