StackRadar

CVE-2022-40897

High

Advisory

Published 23 Dec 2022In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.026
85th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
765
of 17,787 indexed, latest versions
Container images
794
deployed by those charts
Fix available
14 of 14
affected packages

pypa/setuptools vulnerable to Regular Expression Denial of Service (ReDoS)

Carried by container images the latest versions of 765 of 17,787 indexed charts deploy, on 794 images.

Affected packageAffected versionsFixed inImages
setuptoolspypi0.9.8, 20.7.0, 20.8.0, 29.0.1.post20161130+84 more65.5.1763
python-setuptoolsrpm39.2.0-5.el8, 39.2.0-6.el80:39.2.0-6.el8_7.162
setuptoolsdeb45.2.0-1, 59.6.0-1.245.2.0-1ubuntu0.1, 59.6.0-1.2ubuntu0.22.04.153
python-pipdeb1.5.4-1ubuntu4, 8.1.1-2ubuntu0.4, 9.0.1-2.3~ubuntu1, 9.0.1-2.3~ubuntu1.18.04.1+7 more1.5.4-1ubuntu4+esm2, 8.1.1-2ubuntu0.6+esm3, 9.0.1-2.3~ubuntu1.18.04.6, 20.0.2-5ubuntu1.7+1 more52
python-setuptoolsdeb3.3-1ubuntu1, 3.3-1ubuntu2, 20.7.0-1, 39.0.1-2+1 more3.3-1ubuntu2+esm1, 20.7.0-1ubuntu0.1~esm1, 39.0.1-2ubuntu0.1, 44.0.0-2ubuntu0.134
python3x-setuptoolsrpm41.6.0-5.module+el8.5.0+12205+a865257a, 50.3.2-4.module+el8.5.0+12204+548604230:50.3.2-5.module+el8.8.0+21635+a173a6fa6
python39rpm3.9.16-1.module+el8.8.0+18968+3d7b19f0.10:3.9.16-1.module+el8.8.0+20025+f2100191.25
python-chardetrpm3.0.4-7.el80:3.0.4-19.module+el8.4.0+9822+20bf12493
python-idnarpm2.5-5.el80:2.10-3.module+el8.4.0+9822+20bf12493
python-pysocksrpm1.6.8-3.el80:1.7.1-4.module+el8.4.0+9822+20bf12493
python-requestsrpm2.20.0-2.1.el8_1, 2.20.0-3.el8_80:2.25.0-2.module+el8.4.0+9822+20bf12493
python-urllib3rpm1.24.2-5.el80:1.25.10-4.module+el8.5.0+11712+ea2d2be13
python3x-piprpm19.3.1-6.module+el8.7.0+15823+8950cfa70:20.2.4-7.module+el8.6.0+13003+6bb2c4881
python-plyrpm3.9-9.el80:3.11-10.module+el8.4.0+9822+20bf12491
OSV records
GHSA-r9hx-vwmv-q579RHSA-2023:0835RHSA-2024:4421UBUNTU-CVE-2022-40897
Also known as
BIT-setuptools-2022-40897, PYSEC-2022-43012, RHSA-2023:7395, USN-5817-1

Charts affected

765 by stars
ChartLatestAffected imagesRadar Score
minio-standalonewenerme1.0.21 of 1See more

minio-standalone wenerme 1.0.2

1 of the 1 container images this version deploys carry CVE-2022-40897.

Container imageDigestPackageFixed in
minio/minio:RELEASE.2022-01-04T07-41-07Z1484c87239ea
setuptools@39.2.0
python-setuptools@39.2.0-6.el8
65.5.1
0:39.2.0-6.el8_7.1

Open the chart page →

6,138
sambawenerme1.0.01 of 1See more

samba wenerme 1.0.0

1 of the 1 container images this version deploys carry CVE-2022-40897.

Container imageDigestPackageFixed in
wener/samba:4.13.39a42bae466d4
setuptools@51.3.3
65.5.1

Open the chart page →

2,555
temporalwenerme0.15.11 of 13See more

temporal wenerme 0.15.1

1 of the 13 container images this version deploys carry CVE-2022-40897.

Container imageDigestPackageFixed in
temporalio/admin-tools:1.15.135034611d981
setuptools@44.1.1
65.5.1

Open the chart page →

22,665
ceph-csi-cephfswikimedia0.1.81 of 5See more

ceph-csi-cephfs wikimedia 0.1.8

1 of the 5 container images this version deploys carry CVE-2022-40897.

Container imageDigestPackageFixed in
quay.io/cephcsi/cephcsi:v3.7.2f7f8228f17cc
setuptools@39.2.0
65.5.1

Open the chart page →

10,286
ceph-csi-rbdwikimedia0.1.131 of 6See more

ceph-csi-rbd wikimedia 0.1.13

1 of the 6 container images this version deploys carry CVE-2022-40897.

Container imageDigestPackageFixed in
quay.io/cephcsi/cephcsi:v3.7.2f7f8228f17cc
setuptools@39.2.0
65.5.1

Open the chart page →

11,785
docker-hub-rate-limit-exporterwiremindVerified publisher0.3.01 of 1See more

docker-hub-rate-limit-exporter wiremind 0.3.0

1 of the 1 container images this version deploys carry CVE-2022-40897.

Container imageDigestPackageFixed in
viadee/docker-hub-rate-limit-exporter:version-1.52e27e3b3ee56
setuptools@52.0.0
65.5.1

Open the chart page →

1,843
pypiwiremindVerified publisher0.2.11 of 1See more

pypi wiremind 0.2.1

1 of the 1 container images this version deploys carry CVE-2022-40897.

Container imageDigestPackageFixed in
codekoala/pypi:1.2.14a999b2cfff2
setuptools@29.0.1.post20161130
65.5.1

Open the chart page →

423
opendistro-eswitcom-gmbh1.13.31 of 3See more

opendistro-es witcom-gmbh 1.13.3

1 of the 3 container images this version deploys carry CVE-2022-40897.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch:1.13.32acfa1dcc5f8
setuptools@0.9.8
65.5.1

Open the chart page →

5,807
powerdnsadminwitcom-gmbh0.3.41 of 1See more

powerdnsadmin witcom-gmbh 0.3.4

1 of the 1 container images this version deploys carry CVE-2022-40897.

Container imageDigestPackageFixed in
ngoduykhanh/powerdns-admin:v0.2.4ba36ab196d3d
setuptools@51.3.3
65.5.1

Open the chart page →

2,643
workshop-pipelinesworkshop-pipelines0.1.61 of 2See more

workshop-pipelines workshop-pipelines 0.1.6

1 of the 2 container images this version deploys carry CVE-2022-40897.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/workshop-pipelines:lateste383ba3e0966
setuptools@39.2.0
python-setuptools@39.2.0-6.el8
65.5.1
0:39.2.0-6.el8_7.1

Open the chart page →

11,592
xkopsxkops0.1.02 of 5See more

xkops xkops 0.1.0

2 of the 5 container images this version deploys carry CVE-2022-40897.

Container imageDigestPackageFixed in
hamzaarshad10/querybackend:1.6.22c1c3b86a8e7
setuptools@58.1.0
65.5.1
murtazashah46/helmfile:latest4d11726cf803
setuptools@58.1.0
65.5.1

Open the chart page →

13,197
keycloakxzaks2.2.01 of 1See more

keycloakx zaks 2.2.0

1 of the 1 container images this version deploys carry CVE-2022-40897.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0.3b8f2a453a17a
setuptools@39.2.0
python-setuptools@39.2.0-6.el8
65.5.1
0:39.2.0-6.el8_7.1

Open the chart page →

6,016
sockpuppetbrowserzekker6Verified publisher0.1.01 of 1See more

sockpuppetbrowser zekker6 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-40897.

Container imageDigestPackageFixed in
dgtlmoon/sockpuppetbrowser:latestf166a963b550
setuptools@65.5.0
65.5.1

Open the chart page →

1,588
alertmanager-matrix-forwarderzloi-space1.0.11 of 2See more

alertmanager-matrix-forwarder zloi-space 1.0.1

1 of the 2 container images this version deploys carry CVE-2022-40897.

Container imageDigestPackageFixed in
matrixdotorg/pantalaimon:v0.10.4ba6a587fa508
setuptools@57.5.0
65.5.1

Open the chart page →

3,118
grafana-matrix-forwarderzloi-space1.0.01 of 2See more

grafana-matrix-forwarder zloi-space 1.0.0

1 of the 2 container images this version deploys carry CVE-2022-40897.

Container imageDigestPackageFixed in
matrixdotorg/pantalaimon:v0.10.4ba6a587fa508
setuptools@57.5.0
65.5.1

Open the chart page →

1,636

Container images carrying it

794 by charts deploying them

A fixed version is listed for 14 of the 14 affected packages.

Container imageDigestPackageFixed inUsed by
pryorda/vmware_exporter:v0.18.479925e63e59f
setuptools@57.5.0
65.5.1
1
pryorda/vmware_exporter:v0.18.3e0f5ba8b7856
setuptools@57.5.0
65.5.1
1
pschiffe/pdns-admin:0.4.137ebba8c2b8f
setuptools@53.0.0
65.5.1
1
pypiserver/pypiserver:v1.4.2c9250d3c418d
setuptools@50.3.0
65.5.1
1
pysga1996/python-redis-web:latestfdeec30ad482
setuptools@57.5.0
65.5.1
1
redash/redash:25.8.000d813437db5
setuptools@65.5.0
65.5.1
1
redash/redash:10.0.0.b503639392753c0376
setuptools@57.5.0
65.5.1
1
redislabs/redisearch:2.4.1433561794c5c8
setuptools@63.4.2
65.5.1
1
redislabs/redisinsight:1.14.0b03ab1426d0d
setuptools@63.2.0
65.5.1
1
reportportal/service-auto-analyzer:5.7.295ada4a216ce
setuptools@57.5.0
65.5.1
1
reportportal/service-metrics-gatherer:1.1.202a0e6dc11161
setuptools@57.5.0
65.5.1
1
rezachalak/bzen-mongo:1.0.034f694325191
setuptools@45.2.0
65.5.1
1
rhasspy/wyoming-whisper:1.0.080b99ddeef6c
setuptools@52.0.0
65.5.1
1
richardchesterwood/k8s-fleetman-webapp-angular:release2ed7d720878ac
setuptools@33.1.1.post20171031
65.5.1
1
rm3l/mac-oui:1.8.03a5e1f95c132
setuptools@39.2.0
65.5.1
1
roadiehq/community-backstage-image:latestef355bf5b639
setuptools@41.2.0
65.5.1
1
robmarkcole/deepstack-ui:latest410275726459
setuptools@57.4.0
65.5.1
1
robotshop/rs-payment:latest774b52c6180d
setuptools@57.4.0
65.5.1
1
runx1/opta-agent:latest0ca3867d3200
setuptools@62.1.0
65.5.1
1
saltstack/salt:3006.3e9c7906b7a5c
setuptools@58.1.0
65.5.1
1
samueldg/snappass:latest3987195edbe6
setuptools@41.6.0
65.5.1
1
sashafefler/spacecapybara_app:latestf96d7804c0ca
setuptools@57.5.0
65.5.1
1
scrapinghub/splash:3.4.1a5f89bc84606
setuptools@44.0.0
python-pip@9.0.1-2.3~ubuntu1.18.04.1
python-setuptools@39.0.1-2
65.5.1
9.0.1-2.3~ubuntu1.18.04.6
39.0.1-2ubuntu0.1
1
seafileltd/seafile-mc:9.0.106693911bcc40
setuptools@45.2.0
python-pip@20.0.2-5ubuntu1.6
setuptools@45.2.0-1
65.5.1
20.0.2-5ubuntu1.7
45.2.0-1ubuntu0.1
1
seafileltd/seafile-mc:10.0.170628f29c663
setuptools@45.2.0
65.5.1
1
seafileltd/seafile-mc:9.0.97ac833196f60
setuptools@45.2.0
python-pip@20.0.2-5ubuntu1.6
setuptools@45.2.0-1
65.5.1
20.0.2-5ubuntu1.7
45.2.0-1ubuntu0.1
1
seafileltd/seafile-mc:11.0.12d0c66e4621bd
setuptools@59.6.0
65.5.1
1
seafileltd/seafile-mc:8.0.7ed0fcda5e6a9
setuptools@45.2.0
python-pip@20.0.2-5ubuntu1.6
setuptools@45.2.0-1
65.5.1
20.0.2-5ubuntu1.7
45.2.0-1ubuntu0.1
1
searx/searx:1.0.0-211-968b28993dbb3a6d9419
setuptools@47.0.0
65.5.1
1
seldonio/locust-core:0.81d0da98a2d76
setuptools@20.7.0
python-pip@8.1.1-2ubuntu0.4
python-setuptools@20.7.0-1
65.5.1
8.1.1-2ubuntu0.6+esm3
20.7.0-1ubuntu0.1~esm1
1
seldonio/seldon-request-logger:1.11.24e985d2006a8
setuptools@39.2.0
python-setuptools@39.2.0-6.el8
65.5.1
0:39.2.0-6.el8_7.1
1
shaowenchen/ops-controller-manager:latest26da43bb5b66
setuptools@59.6.0
65.5.1
1
shaowenchen/ops-server:latest315444f703f4
setuptools@59.6.0
65.5.1
1
sharanalwar/redchef-backend:latest8d3cab80df49
setuptools@58.1.0
65.5.1
1
signalen/classification:ad60447d1733473e30ab0a3ba53d58141cc1d2509496ae672877
setuptools@40.8.0
65.5.1
1
skylenet/ethereum-genesis-generator:latest210353ce7c89
setuptools@52.0.0
65.5.1
1
snipe/snipe-it:v6.0.1455fb7636a98c
setuptools@45.2.0-1
45.2.0-1ubuntu0.1
1
socialmediamacroscope/autophrase:0.1.570fb11d4f531
setuptools@45.2.0
65.5.1
1
socialmediamacroscope/classification_predict:0.1.24fb86885d64d
setuptools@57.5.0
65.5.1
1
socialmediamacroscope/classification_split:0.1.24bfda60829fe
setuptools@57.5.0
65.5.1
1
socialmediamacroscope/classification_train:0.1.207477060bba8
setuptools@57.5.0
65.5.1
1
socialmediamacroscope/clowder_create_collection:0.1.0c969f7677983
setuptools@57.5.0
65.5.1
1
socialmediamacroscope/clowder_create_dataset:0.1.09b4211832429
setuptools@57.5.0
65.5.1
1
socialmediamacroscope/clowder_create_space:0.1.0999f2ff2c128
setuptools@57.5.0
65.5.1
1
socialmediamacroscope/clowder_list:0.1.051cb17626519
setuptools@57.5.0
65.5.1
1
socialmediamacroscope/clowder_upload_file:0.1.274e35f64db68
setuptools@57.5.0
65.5.1
1
socialmediamacroscope/collect_reddit_comment:0.1.219d3d26d53ee
setuptools@39.0.1
65.5.1
1
socialmediamacroscope/histogram:0.1.26418f9bdb4d2
setuptools@57.5.0
65.5.1
1
socialmediamacroscope/image_crawler:0.1.2f508216be63c
setuptools@39.0.1
65.5.1
1
socialmediamacroscope/network_analysis:0.1.3b351c21422e6
setuptools@57.5.0
65.5.1
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.