CVE-2022-40897
HighAdvisory
Published 23 Dec 2022In the index since 5 Sept 2026
- Severity
- High
- worst across findings
- CVSS
- 7.5
- base score, highest
- EPSS
- 0.026
- 85th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 765
- of 17,787 indexed, latest versions
- Container images
- 794
- deployed by those charts
- Fix available
- 14 of 14
- affected packages
pypa/setuptools vulnerable to Regular Expression Denial of Service (ReDoS)
Carried by container images the latest versions of 765 of 17,787 indexed charts deploy, on 794 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| setuptoolspypi | 0.9.8, 20.7.0, 20.8.0, 29.0.1.post20161130+84 more | 65.5.1 | 763 |
| python-setuptoolsrpm | 39.2.0-5.el8, 39.2.0-6.el8 | 0:39.2.0-6.el8_7.1 | 62 |
| setuptoolsdeb | 45.2.0-1, 59.6.0-1.2 | 45.2.0-1ubuntu0.1, 59.6.0-1.2ubuntu0.22.04.1 | 53 |
| python-pipdeb | 1.5.4-1ubuntu4, 8.1.1-2ubuntu0.4, 9.0.1-2.3~ubuntu1, 9.0.1-2.3~ubuntu1.18.04.1+7 more | 1.5.4-1ubuntu4+esm2, 8.1.1-2ubuntu0.6+esm3, 9.0.1-2.3~ubuntu1.18.04.6, 20.0.2-5ubuntu1.7+1 more | 52 |
| python-setuptoolsdeb | 3.3-1ubuntu1, 3.3-1ubuntu2, 20.7.0-1, 39.0.1-2+1 more | 3.3-1ubuntu2+esm1, 20.7.0-1ubuntu0.1~esm1, 39.0.1-2ubuntu0.1, 44.0.0-2ubuntu0.1 | 34 |
| python3x-setuptoolsrpm | 41.6.0-5.module+el8.5.0+12205+a865257a, 50.3.2-4.module+el8.5.0+12204+54860423 | 0:50.3.2-5.module+el8.8.0+21635+a173a6fa | 6 |
| python39rpm | 3.9.16-1.module+el8.8.0+18968+3d7b19f0.1 | 0:3.9.16-1.module+el8.8.0+20025+f2100191.2 | 5 |
| python-chardetrpm | 3.0.4-7.el8 | 0:3.0.4-19.module+el8.4.0+9822+20bf1249 | 3 |
| python-idnarpm | 2.5-5.el8 | 0:2.10-3.module+el8.4.0+9822+20bf1249 | 3 |
| python-pysocksrpm | 1.6.8-3.el8 | 0:1.7.1-4.module+el8.4.0+9822+20bf1249 | 3 |
| python-requestsrpm | 2.20.0-2.1.el8_1, 2.20.0-3.el8_8 | 0:2.25.0-2.module+el8.4.0+9822+20bf1249 | 3 |
| python-urllib3rpm | 1.24.2-5.el8 | 0:1.25.10-4.module+el8.5.0+11712+ea2d2be1 | 3 |
| python3x-piprpm | 19.3.1-6.module+el8.7.0+15823+8950cfa7 | 0:20.2.4-7.module+el8.6.0+13003+6bb2c488 | 1 |
| python-plyrpm | 3.9-9.el8 | 0:3.11-10.module+el8.4.0+9822+20bf1249 | 1 |
- OSV records
- GHSA-r9hx-vwmv-q579RHSA-2023:0835RHSA-2024:4421UBUNTU-CVE-2022-40897
- Also known as
- BIT-setuptools-2022-40897, PYSEC-2022-43012, RHSA-2023:7395, USN-5817-1
Charts affected
765 by stars
| Chart | Latest | Affected images | Radar Score |
|---|---|---|---|
| minio-standalonewenerme | 1.0.2 | 1 of 1See more | 6,138 |
| sambawenerme | 1.0.0 | 1 of 1See more | 2,555 |
| temporalwenerme | 0.15.1 | 1 of 13See more | 22,665 |
| ceph-csi-cephfswikimedia | 0.1.8 | 1 of 5See more | 10,286 |
| ceph-csi-rbdwikimedia | 0.1.13 | 1 of 6See more | 11,785 |
| docker-hub-rate-limit-exporterwiremindVerified publisher | 0.3.0 | 1 of 1See more | 1,843 |
| pypiwiremindVerified publisher | 0.2.1 | 1 of 1See more | 423 |
| opendistro-eswitcom-gmbh | 1.13.3 | 1 of 3See more | 5,807 |
| powerdnsadminwitcom-gmbh | 0.3.4 | 1 of 1See more | 2,643 |
| workshop-pipelinesworkshop-pipelines | 0.1.6 | 1 of 2See more | 11,592 |
| xkopsxkops | 0.1.0 | 2 of 5See more | 13,197 |
| keycloakxzaks | 2.2.0 | 1 of 1See more | 6,016 |
| sockpuppetbrowserzekker6Verified publisher | 0.1.0 | 1 of 1See more | 1,588 |
| alertmanager-matrix-forwarderzloi-space | 1.0.1 | 1 of 2See more | 3,118 |
| grafana-matrix-forwarderzloi-space | 1.0.0 | 1 of 2See more | 1,636 |
Container images carrying it
794 by charts deploying them
A fixed version is listed for 14 of the 14 affected packages.