Junglewise Threat Intelligence

CVE-2022-40897: PYSEC-2022-43012 - Python Packaging Authority (PyPA) setuptools before 65.5.1 allows remote attackers to cause a denial of service via HTML in a crafted packag

CVE-2022-40897 · Severity: low · CVSS 3.1 · Published 2022-12-23

Technologies: setuptools (PyPI). Vendors: PyPI.

Executive brief

Python Packaging Authority (PyPA) setuptools before 65.5.1 allows remote attackers to cause a denial of service via HTML in a crafted package or custom PackageIndex page. There is a Regular Expression Denial of Service (ReDoS) in package_index.py.

Affected products

  • PyPI setuptools

Related threats