yocto ▾
›
kirkstone ▾
›
vulnerability
›
CVE-2022-40897
Component Overview
Vulnerability Overview
Name
CVE-2022-40897
Source
NVD (
link
)
Debian (
link
)
Description
Python Packaging Authority (PyPA) setuptools before 65.5.1 allows remote attackers to cause a denial of service via HTML in a crafted package or custom PackageIndex page. There is a Regular Expression Denial of Service (ReDoS) in package_index.py.
CWEs
CWE-1333
CWE-1333
Published Date
Dec 23, 2022
Updated Date
Jun 17, 2026
Workaround
-
Advisories
https://github.com/pypa/setuptools/blob/fe8a98e696241487ba6ac9f91faa38ade939ec5d/setuptools/package_index.py#L200
Third Party Advisory
https://github.com/pypa/setuptools/commit/43a9c9bfa6aa626ec2a22540bea28d2ca77964be
Patch
https://github.com/pypa/setuptools/compare/v65.5.0...v65.5.1
Release Notes
https://pyup.io/posts/pyup-discovers-redos-vulnerabilities-in-top-python-packages/
Exploit
https://pyup.io/vulnerabilities/CVE-2022-40897/52495/
Third Party Advisory
https://github.com/pypa/setuptools/blob/fe8a98e696241487ba6ac9f91faa38ade939ec5d/setuptools/package_index.py#L200
Third Party Advisory
https://github.com/pypa/setuptools/commit/43a9c9bfa6aa626ec2a22540bea28d2ca77964be
Patch
https://github.com/pypa/setuptools/compare/v65.5.0...v65.5.1
Release Notes
https://pyup.io/posts/pyup-discovers-redos-vulnerabilities-in-top-python-packages/
Exploit
https://pyup.io/vulnerabilities/CVE-2022-40897/52495/
Third Party Advisory
Analysis
#
Affected Component
Analysis
python3-setuptools
Patched
Vulnerability Ratings
#
5.9
CVSSv31
5.9
CVSSv31
NaN
other
Others affected components
#
Name
Project
Project Version
Version
Status
python-setuptools
buildroot
2025.02.x
80.9.0
Not Affected
python-setuptools
buildroot
master
80.9.0
Not Affected
python-setuptools
openwrt
master
82.0.1-r2
Not Affected
python-setuptools
openwrt
openwrt-25.12
80.9.0-r3
Not Affected
python3-setuptools
yocto
master
82.0.1
Not Affected
python3-setuptools
yocto
scarthgap
69.1.1
Not Affected
Resolved with patches
#
python3-setuptools (yocto:kirkstone)
#
Title
Author
Resolve
1
Limit the amount of whitespace to search/backtrack. Fixes
Narpat Mali <narpat.mali@windriver.com>
CVE-2022-40897