ZeroHour

CVE-2022-40897

PoC
CVSS 3.1
5.9 medium
EPSS
3%p85
Published
()
Modified
Description

Python Packaging Authority (PyPA) setuptools before 65.5.1 allows remote attackers to cause a denial of service via HTML in a crafted package or custom PackageIndex page. There is a Regular Expression Denial of Service (ReDoS) in package_index.py.

Vendors
python
Products
setuptools
Weakness
CWE-1333
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.