PT-2022-7152 · Python Packaging Authority+8 · Wheel+8

Published

2022-11-16

·

Updated

2025-12-05

·

CVE-2022-40898

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Python Packaging Authority (PyPA) Wheel versions 0.37.1 and earlier
Description The issue is related to an uncontrolled resource consumption in the Python Packaging Authority (PyPA) Wheel, which can be exploited by a remote attacker to cause a denial of service. This is achieved through attacker-controlled input to the wheel cli, specifically via a vulnerable regular expression used to verify the validity of Wheel file names.
Recommendations For versions 0.37.1 and earlier, update to version 0.38.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the wheel cli to minimize the risk of exploitation.

Exploit

Fix

DoS

RCE

Resource Exhaustion

Weakness Enumeration

Related Identifiers

ALSA-2023:6712
ALT-PU-2022-3086
AZL-12098
BDU:2023-08101
CVE-2022-40898
GHSA-QWMP-2CF2-G9G6
INFSA-2023_6712
MGASA-2023-0218
OESA-2023-1904
OPENSUSE-SU-2023_0088-1
OPENSUSE-SU-2024:12645-1
OPENSUSE-SU-2024:13214-1
PYSEC-2022-43017
RHSA-2023:6712
RHSA-2023:6793
RHSA-2023_6712
RHSA-2024:10761
RHSA-2024_10761
SUSE-SU-2023:0088-1
SUSE-SU-2023:0088-2
SUSE-SU-2023:0089-1
SUSE-SU-2023_0088-1
SUSE-SU-2023_0088-2
SUSE-SU-2023_0089-1
USN-5821-1
USN-5821-2
USN-5821-3
USN-5821-4

Affected Products

Alt Linux
Almalinux
Debian
Linuxmint
Red Hat
Red Os
Suse
Ubuntu
Wheel