Python Packaging Authority (PyPA) setuptools before 65.5.1 allows remote attackers to cause a denial of service via HTML in a crafted package or custom PackageIndex page. There is a Regular Expression Denial of Service (ReDoS) in package_index.py.
References
Configurations
History
04 Nov 2025, 16:15
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Information
Published : 2022-12-23 00:15
Updated : 2025-11-04 16:15
NVD link : CVE-2022-40897
Mitre link : CVE-2022-40897
CVE.ORG link : CVE-2022-40897
JSON object : View
Products Affected
python
- setuptools
CWE
CWE-1333
Inefficient Regular Expression Complexity
