CVE-2022-40897 is a Regular Expression Denial of Service (ReDoS) vulnerability affecting Python Packaging Authority (PyPA) setuptools versions prior to 65.5.1. An unauthenticated remote attacker can exploit this by submitting crafted HTML in a package or custom PackageIndex page, leading to a denial of service. The vulnerability has a CVSS score of 5.9 (Medium) due to its high impact on availability and low attack complexity, although it requires no user interaction. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 65.5.1CPE matchmatch criteria | cpe:2.3:a:python:setuptools:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Third-Party Package Updates in Splunk User Behavior Analytics (UBA) - April 2025
Apr 29, 2025pypa/setuptools vulnerable to Regular Expression Denial of Service (ReDoS)
Dec 23, 2022pypa-setuptools: Regular Expression Denial of Service (ReDoS) in package_index.py
Dec 22, 2022Python Packaging Authority (PyPA) setuptools before 65.5.1 allows remote attackers to cause a denial of service via HTML in a crafted package or custom PackageIndex page. There is a Regular Expression Denial of Service (ReDoS) in package_index.py.
Dec 13, 2022