CVE-2022-40897High· 7.5▾ Twilightpypa/setuptools vulnerable to Regular Expression Denial of Service (ReDoS)
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.5 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 7.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
2.6%
Python Packaging Authority (PyPA)'s setuptools is a library designed to facilitate packaging Python projects. Setuptools version 65.5.0 and earlier could allow remote attackers to cause a denial of service by fetching malicious HTML from a PyPI package or custom PackageIndex page due to a vulnerable Regular Expression in package_index. This has been patched in version 65.5.1.
setuptools < 65.5.1Upgrade to a patched release:
setuptools 65.5.1Connected by shared product, vendor, weakness, or advisory.
CVE-2024-6345High· 8.8setuptools vulnerable to Command Injection via package URL
CVE-2025-47273Highsetuptools has a path traversal vulnerability in PackageIndex.download that leads to Arbitrary File Write
CVE-2026-59890Medium· 6.1setuptools: MANIFEST.in exclusion bypass in sdist via Unicode normalization collision (NFC/NFD) on macOS APFS/HFS+