StackRadar

CVE-2022-40897

High

Advisory

Published 23 Dec 2022In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.026
85th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
765
of 17,787 indexed, latest versions
Container images
794
deployed by those charts
Fix available
14 of 14
affected packages

pypa/setuptools vulnerable to Regular Expression Denial of Service (ReDoS)

Carried by container images the latest versions of 765 of 17,787 indexed charts deploy, on 794 images.

Affected packageAffected versionsFixed inImages
setuptoolspypi0.9.8, 20.7.0, 20.8.0, 29.0.1.post20161130+84 more65.5.1763
python-setuptoolsrpm39.2.0-5.el8, 39.2.0-6.el80:39.2.0-6.el8_7.162
setuptoolsdeb45.2.0-1, 59.6.0-1.245.2.0-1ubuntu0.1, 59.6.0-1.2ubuntu0.22.04.153
python-pipdeb1.5.4-1ubuntu4, 8.1.1-2ubuntu0.4, 9.0.1-2.3~ubuntu1, 9.0.1-2.3~ubuntu1.18.04.1+7 more1.5.4-1ubuntu4+esm2, 8.1.1-2ubuntu0.6+esm3, 9.0.1-2.3~ubuntu1.18.04.6, 20.0.2-5ubuntu1.7+1 more52
python-setuptoolsdeb3.3-1ubuntu1, 3.3-1ubuntu2, 20.7.0-1, 39.0.1-2+1 more3.3-1ubuntu2+esm1, 20.7.0-1ubuntu0.1~esm1, 39.0.1-2ubuntu0.1, 44.0.0-2ubuntu0.134
python3x-setuptoolsrpm41.6.0-5.module+el8.5.0+12205+a865257a, 50.3.2-4.module+el8.5.0+12204+548604230:50.3.2-5.module+el8.8.0+21635+a173a6fa6
python39rpm3.9.16-1.module+el8.8.0+18968+3d7b19f0.10:3.9.16-1.module+el8.8.0+20025+f2100191.25
python-chardetrpm3.0.4-7.el80:3.0.4-19.module+el8.4.0+9822+20bf12493
python-idnarpm2.5-5.el80:2.10-3.module+el8.4.0+9822+20bf12493
python-pysocksrpm1.6.8-3.el80:1.7.1-4.module+el8.4.0+9822+20bf12493
python-requestsrpm2.20.0-2.1.el8_1, 2.20.0-3.el8_80:2.25.0-2.module+el8.4.0+9822+20bf12493
python-urllib3rpm1.24.2-5.el80:1.25.10-4.module+el8.5.0+11712+ea2d2be13
python3x-piprpm19.3.1-6.module+el8.7.0+15823+8950cfa70:20.2.4-7.module+el8.6.0+13003+6bb2c4881
python-plyrpm3.9-9.el80:3.11-10.module+el8.4.0+9822+20bf12491
OSV records
GHSA-r9hx-vwmv-q579RHSA-2023:0835RHSA-2024:4421UBUNTU-CVE-2022-40897
Also known as
BIT-setuptools-2022-40897, PYSEC-2022-43012, RHSA-2023:7395, USN-5817-1

Charts affected

765 by stars
ChartLatestAffected imagesRadar Score
minio-standalonewenerme1.0.21 of 1See more

minio-standalone wenerme 1.0.2

1 of the 1 container images this version deploys carry CVE-2022-40897.

Container imageDigestPackageFixed in
minio/minio:RELEASE.2022-01-04T07-41-07Z1484c87239ea
setuptools@39.2.0
python-setuptools@39.2.0-6.el8
65.5.1
0:39.2.0-6.el8_7.1

Open the chart page →

6,138
sambawenerme1.0.01 of 1See more

samba wenerme 1.0.0

1 of the 1 container images this version deploys carry CVE-2022-40897.

Container imageDigestPackageFixed in
wener/samba:4.13.39a42bae466d4
setuptools@51.3.3
65.5.1

Open the chart page →

2,555
temporalwenerme0.15.11 of 13See more

temporal wenerme 0.15.1

1 of the 13 container images this version deploys carry CVE-2022-40897.

Container imageDigestPackageFixed in
temporalio/admin-tools:1.15.135034611d981
setuptools@44.1.1
65.5.1

Open the chart page →

22,665
ceph-csi-cephfswikimedia0.1.81 of 5See more

ceph-csi-cephfs wikimedia 0.1.8

1 of the 5 container images this version deploys carry CVE-2022-40897.

Container imageDigestPackageFixed in
quay.io/cephcsi/cephcsi:v3.7.2f7f8228f17cc
setuptools@39.2.0
65.5.1

Open the chart page →

10,286
ceph-csi-rbdwikimedia0.1.131 of 6See more

ceph-csi-rbd wikimedia 0.1.13

1 of the 6 container images this version deploys carry CVE-2022-40897.

Container imageDigestPackageFixed in
quay.io/cephcsi/cephcsi:v3.7.2f7f8228f17cc
setuptools@39.2.0
65.5.1

Open the chart page →

11,785
docker-hub-rate-limit-exporterwiremindVerified publisher0.3.01 of 1See more

docker-hub-rate-limit-exporter wiremind 0.3.0

1 of the 1 container images this version deploys carry CVE-2022-40897.

Container imageDigestPackageFixed in
viadee/docker-hub-rate-limit-exporter:version-1.52e27e3b3ee56
setuptools@52.0.0
65.5.1

Open the chart page →

1,843
pypiwiremindVerified publisher0.2.11 of 1See more

pypi wiremind 0.2.1

1 of the 1 container images this version deploys carry CVE-2022-40897.

Container imageDigestPackageFixed in
codekoala/pypi:1.2.14a999b2cfff2
setuptools@29.0.1.post20161130
65.5.1

Open the chart page →

423
opendistro-eswitcom-gmbh1.13.31 of 3See more

opendistro-es witcom-gmbh 1.13.3

1 of the 3 container images this version deploys carry CVE-2022-40897.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch:1.13.32acfa1dcc5f8
setuptools@0.9.8
65.5.1

Open the chart page →

5,807
powerdnsadminwitcom-gmbh0.3.41 of 1See more

powerdnsadmin witcom-gmbh 0.3.4

1 of the 1 container images this version deploys carry CVE-2022-40897.

Container imageDigestPackageFixed in
ngoduykhanh/powerdns-admin:v0.2.4ba36ab196d3d
setuptools@51.3.3
65.5.1

Open the chart page →

2,643
workshop-pipelinesworkshop-pipelines0.1.61 of 2See more

workshop-pipelines workshop-pipelines 0.1.6

1 of the 2 container images this version deploys carry CVE-2022-40897.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/workshop-pipelines:lateste383ba3e0966
setuptools@39.2.0
python-setuptools@39.2.0-6.el8
65.5.1
0:39.2.0-6.el8_7.1

Open the chart page →

11,592
xkopsxkops0.1.02 of 5See more

xkops xkops 0.1.0

2 of the 5 container images this version deploys carry CVE-2022-40897.

Container imageDigestPackageFixed in
hamzaarshad10/querybackend:1.6.22c1c3b86a8e7
setuptools@58.1.0
65.5.1
murtazashah46/helmfile:latest4d11726cf803
setuptools@58.1.0
65.5.1

Open the chart page →

13,197
keycloakxzaks2.2.01 of 1See more

keycloakx zaks 2.2.0

1 of the 1 container images this version deploys carry CVE-2022-40897.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0.3b8f2a453a17a
setuptools@39.2.0
python-setuptools@39.2.0-6.el8
65.5.1
0:39.2.0-6.el8_7.1

Open the chart page →

6,016
sockpuppetbrowserzekker6Verified publisher0.1.01 of 1See more

sockpuppetbrowser zekker6 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-40897.

Container imageDigestPackageFixed in
dgtlmoon/sockpuppetbrowser:latestf166a963b550
setuptools@65.5.0
65.5.1

Open the chart page →

1,588
alertmanager-matrix-forwarderzloi-space1.0.11 of 2See more

alertmanager-matrix-forwarder zloi-space 1.0.1

1 of the 2 container images this version deploys carry CVE-2022-40897.

Container imageDigestPackageFixed in
matrixdotorg/pantalaimon:v0.10.4ba6a587fa508
setuptools@57.5.0
65.5.1

Open the chart page →

3,118
grafana-matrix-forwarderzloi-space1.0.01 of 2See more

grafana-matrix-forwarder zloi-space 1.0.0

1 of the 2 container images this version deploys carry CVE-2022-40897.

Container imageDigestPackageFixed in
matrixdotorg/pantalaimon:v0.10.4ba6a587fa508
setuptools@57.5.0
65.5.1

Open the chart page →

1,636

Container images carrying it

794 by charts deploying them

A fixed version is listed for 14 of the 14 affected packages.

Container imageDigestPackageFixed inUsed by
quay.io/keycloak/keycloak:20.0.3b8f2a453a17a
setuptools@39.2.0
python-setuptools@39.2.0-6.el8
65.5.1
0:39.2.0-6.el8_7.1
1
quay.io/keycloak/keycloak-operator:20.0.2b1710745fa64
setuptools@39.2.0
python-setuptools@39.2.0-6.el8
65.5.1
0:39.2.0-6.el8_7.1
1
quay.io/kiali/kiali-operator:v2.32.096c5264d54ab
setuptools@53.0.0
65.5.1
1
quay.io/kiwigrid/k8s-sidecar:1.10.718feb3906286
setuptools@53.0.0
65.5.1
1
quay.io/kiwigrid/k8s-sidecar:1.15.61f025ae37b7b
setuptools@60.9.3
65.5.1
1
quay.io/kiwigrid/k8s-sidecar:1.21.0710e23b489c5
setuptools@65.5.0
65.5.1
1
quay.io/kiwigrid/k8s-sidecar:1.15.1a25886092fa4
setuptools@57.5.0
65.5.1
1
quay.io/maximilianopizarro/custom-rhcl-console:v0.1.270bb0cabd653
setuptools@53.0.0
65.5.1
1
quay.io/maximilianopizarro/neuralbank-frontend:latest5f4572ef6d6f
setuptools@53.0.0
65.5.1
1
quay.io/maximilianopizarro/neuroface-backend:v1.4.13194d46df0f9
setuptools@53.0.0
65.5.1
1
quay.io/maximilianopizarro/neuroface-backend:latestcba71dc08c8a
setuptools@53.0.0
65.5.1
1
quay.io/maximilianopizarro/neuroface-frontend:v1.4.1841b70cd1424
setuptools@53.0.0
65.5.1
1
quay.io/maximilianopizarro/neuroface-frontend:latestdcf24040cc77
setuptools@53.0.0
65.5.1
1
quay.io/maximilianopizarro/nfl-wallet-webapp:1.0.13fead5702be7
setuptools@39.2.0
65.5.1
1
quay.io/maximilianopizarro/workshop-pipelines:lateste383ba3e0966
setuptools@39.2.0
python-setuptools@39.2.0-6.el8
65.5.1
0:39.2.0-6.el8_7.1
1
quay.io/mongodb/farm-intro-backend:0.11a9ce0b8fbd4
setuptools@57.5.0
65.5.1
1
quay.io/nird-toolkit/jupyterhub-server:20221215-e6aa80ecae8c0622533
setuptools@58.1.0
65.5.1
1
quay.io/openshift/origin-cli:4.66722d5041b47
setuptools@39.2.0
python-setuptools@39.2.0-5.el8
65.5.1
0:39.2.0-6.el8_7.1
1
quay.io/openshift/origin-console:4.10.00bbe8b451fa3
setuptools@39.2.0
python-setuptools@39.2.0-5.el8
65.5.1
0:39.2.0-6.el8_7.1
1
quay.io/openshift/origin-jenkins-agent-base:latestc241c971aef8
setuptools@39.2.0
65.5.1
1
quay.io/opsmxpublic/awsgit:v2-openssh0d21ba756f44
setuptools@52.0.0
65.5.1
1
quay.io/opsmxpublic/awsgit:v3-js15a6faada3d4
setuptools@52.0.0
65.5.1
1
quay.io/opsmxpublic/ubi8-gate:isd-spin-2025.10.01-5c720954-2025112608102b3554029737
setuptools@39.2.0
65.5.1
1
quay.io/opsmxpublic/ubi8-oes-audit-client:isd-spin-2025.10.01-cb1bfce-20251126103732a5b1887eab
setuptools@39.2.0
65.5.1
1
quay.io/opsmxpublic/ubi8-oes-autopilot:isd-spin-2025.10.01-af26a30d4-20251126105458bd0bcf72f9
setuptools@39.2.0
65.5.1
1
quay.io/opsmxpublic/ubi8-oes-db:v3.0.089ee6493af89
setuptools@39.2.0
python-setuptools@39.2.0-6.el8
65.5.1
0:39.2.0-6.el8_7.1
1
quay.io/opsmxpublic/ubi8-oes-platform:isd-spin-2025.10.01-a7c191ec-2025112611228ed603ab7417
setuptools@39.2.0
65.5.1
1
quay.io/opsmxpublic/ubi8-oes-ui:isd-spin-2025.10.01-e6f6f01-2025121006405d934bb66884
setuptools@39.2.0
65.5.1
1
quay.io/redhat-ai-dev/chatbot:latest59fe607dfdf2
setuptools@53.0.0
65.5.1
1
quay.io/redhat-appstudio/appstudio-utils:dbbdd82734232e6289e8fbae5b4c858481a7c0577b4202c25b67
setuptools@53.0.0
65.5.1
1
quay.io/rht-labs/stack-do500:3.0.86ba82beff18e
setuptools@39.2.0
python-setuptools@39.2.0-6.el8
65.5.1
0:39.2.0-6.el8_7.1
1
quay.io/seamware/consent-facade:0.0.14be844c750c7e
setuptools@39.2.0
65.5.1
1
quay.io/soketi/pws:0.8-16-alpine399d2e6b10ef
setuptools@58.2.0
65.5.1
1
quay.io/stackgres/operator:1.19.1f241b0b20326
setuptools@50.3.2
65.5.1
1
quay.io/strimzi/operator:0.36.1e9e03b31007c
setuptools@39.2.0
65.5.1
1
quay.io/wi_stefan/dss-validation-service:0.0.18e928db29ee1
setuptools@39.2.0
65.5.1
1
quay.io/yushiwho/api:e1f9d77e0d9b93dbf2b
setuptools@57.5.0
65.5.1
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/mongodb:4.4.5cf72810d33f5
setuptools@39.2.0
python-setuptools@39.2.0-6.el8
65.5.1
0:39.2.0-6.el8_7.1
1
registry.gitlab.com/infinitydon/registry/open5gs-aio:v2.2.2f6385712935f
setuptools@45.2.0
python-pip@20.0.2-5ubuntu1.1
setuptools@45.2.0-1
65.5.1
20.0.2-5ubuntu1.7
45.2.0-1ubuntu0.1
1
registry.gitlab.com/open-forms/design-catalogue:latestf21f19346b29
setuptools@51.0.0
65.5.1
1
registry.gitlab.com/open-forms/forms-catalogue:latest4eaf9c911f33
setuptools@57.5.0
65.5.1
1
registry.gitlab.com/open-forms/request-registry:latest0886cbbc5f95
setuptools@57.5.0
65.5.1
1
registry.gitlab.com/radiology/infrastructure/study-governor:8.0.04e7faf6f8d5f
setuptools@58.1.0
65.5.1
1
registry.gitlab.com/xrow-public/helm-iframely/iframely:2.3.5fcf07d5ff7e2
setuptools@53.0.0
65.5.1
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.