← back
CVE-2022-40897mediumCWE-1333

CVE-2022-40897

13Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 5.9epss 2.6%
exploitation probability
2.6%top 15% of all CVEs
observed exploitation
nono source reports it
In short

A flaw in setuptools allows attackers to crash the package installation process by creating specially crafted HTML content. When processing package information, a vulnerable regular expression consumes excessive resources and freezes the system.

Technical detail

A ReDoS vulnerability in setuptools' package_index.py allows remote attackers to trigger denial of service by serving malicious HTML in crafted package metadata or custom PackageIndex pages. The vulnerable regex pattern causes exponential backtracking when processing adversarial input, impacting availability during package installation or index queries.

Summary generated and translated by AI from the official description.
Python Packaging Authority (PyPA) setuptools before 65.5.1 allows remote attackers to cause a denial of service via HTML in a crafted package or custom PackageIndex page. There is a Regular Expression Denial of Service (ReDoS) in package_index.py.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected products
n/a · n/a