StackRadar

CVE-2022-40897

High

Advisory

Published 23 Dec 2022In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.026
85th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
757
of 17,787 indexed, latest versions
Container images
786
deployed by those charts
Fix available
14 of 14
affected packages

pypa/setuptools vulnerable to Regular Expression Denial of Service (ReDoS)

Carried by container images the latest versions of 757 of 17,787 indexed charts deploy, on 786 images.

Affected packageAffected versionsFixed inImages
setuptoolspypi0.9.8, 20.7.0, 20.8.0, 29.0.1.post20161130+83 more65.5.1755
python-setuptoolsrpm39.2.0-5.el8, 39.2.0-6.el80:39.2.0-6.el8_7.162
setuptoolsdeb45.2.0-1, 59.6.0-1.245.2.0-1ubuntu0.1, 59.6.0-1.2ubuntu0.22.04.153
python-pipdeb1.5.4-1ubuntu4, 8.1.1-2ubuntu0.4, 9.0.1-2.3~ubuntu1, 9.0.1-2.3~ubuntu1.18.04.1+7 more1.5.4-1ubuntu4+esm2, 8.1.1-2ubuntu0.6+esm3, 9.0.1-2.3~ubuntu1.18.04.6, 20.0.2-5ubuntu1.7+1 more52
python-setuptoolsdeb3.3-1ubuntu1, 3.3-1ubuntu2, 20.7.0-1, 39.0.1-2+1 more3.3-1ubuntu2+esm1, 20.7.0-1ubuntu0.1~esm1, 39.0.1-2ubuntu0.1, 44.0.0-2ubuntu0.134
python3x-setuptoolsrpm41.6.0-5.module+el8.5.0+12205+a865257a, 50.3.2-4.module+el8.5.0+12204+548604230:50.3.2-5.module+el8.8.0+21635+a173a6fa6
python39rpm3.9.16-1.module+el8.8.0+18968+3d7b19f0.10:3.9.16-1.module+el8.8.0+20025+f2100191.25
python-chardetrpm3.0.4-7.el80:3.0.4-19.module+el8.4.0+9822+20bf12493
python-idnarpm2.5-5.el80:2.10-3.module+el8.4.0+9822+20bf12493
python-pysocksrpm1.6.8-3.el80:1.7.1-4.module+el8.4.0+9822+20bf12493
python-requestsrpm2.20.0-2.1.el8_1, 2.20.0-3.el8_80:2.25.0-2.module+el8.4.0+9822+20bf12493
python-urllib3rpm1.24.2-5.el80:1.25.10-4.module+el8.5.0+11712+ea2d2be13
python3x-piprpm19.3.1-6.module+el8.7.0+15823+8950cfa70:20.2.4-7.module+el8.6.0+13003+6bb2c4881
python-plyrpm3.9-9.el80:3.11-10.module+el8.4.0+9822+20bf12491
OSV records
GHSA-r9hx-vwmv-q579RHSA-2023:0835RHSA-2024:4421UBUNTU-CVE-2022-40897
Also known as
BIT-setuptools-2022-40897, PYSEC-2022-43012, RHSA-2023:7395, USN-5817-1

Charts affected

757 by stars
ChartLatestAffected imagesRadar Score
powerdnsadminwitcom-gmbh0.3.41 of 1See more

powerdnsadmin witcom-gmbh 0.3.4

1 of the 1 container images this version deploys carry CVE-2022-40897.

Container imageDigestPackageFixed in
ngoduykhanh/powerdns-admin:v0.2.4ba36ab196d3d
setuptools@51.3.3
65.5.1

Open the chart page →

2,643
workshop-pipelinesworkshop-pipelines0.1.61 of 2See more

workshop-pipelines workshop-pipelines 0.1.6

1 of the 2 container images this version deploys carry CVE-2022-40897.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/workshop-pipelines:lateste383ba3e0966
setuptools@39.2.0
python-setuptools@39.2.0-6.el8
65.5.1
0:39.2.0-6.el8_7.1

Open the chart page →

11,577
xkopsxkops0.1.02 of 5See more

xkops xkops 0.1.0

2 of the 5 container images this version deploys carry CVE-2022-40897.

Container imageDigestPackageFixed in
hamzaarshad10/querybackend:1.6.22c1c3b86a8e7
setuptools@58.1.0
65.5.1
murtazashah46/helmfile:latest4d11726cf803
setuptools@58.1.0
65.5.1

Open the chart page →

13,677
keycloakxzaks2.2.01 of 1See more

keycloakx zaks 2.2.0

1 of the 1 container images this version deploys carry CVE-2022-40897.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0.3b8f2a453a17a
setuptools@39.2.0
python-setuptools@39.2.0-6.el8
65.5.1
0:39.2.0-6.el8_7.1

Open the chart page →

6,016
sockpuppetbrowserzekker6Verified publisher0.1.01 of 1See more

sockpuppetbrowser zekker6 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-40897.

Container imageDigestPackageFixed in
dgtlmoon/sockpuppetbrowser:latestf166a963b550
setuptools@65.5.0
65.5.1

Open the chart page →

1,589
alertmanager-matrix-forwarderzloi-space1.0.11 of 2See more

alertmanager-matrix-forwarder zloi-space 1.0.1

1 of the 2 container images this version deploys carry CVE-2022-40897.

Container imageDigestPackageFixed in
matrixdotorg/pantalaimon:v0.10.4ba6a587fa508
setuptools@57.5.0
65.5.1

Open the chart page →

3,118
grafana-matrix-forwarderzloi-space1.0.01 of 2See more

grafana-matrix-forwarder zloi-space 1.0.0

1 of the 2 container images this version deploys carry CVE-2022-40897.

Container imageDigestPackageFixed in
matrixdotorg/pantalaimon:v0.10.4ba6a587fa508
setuptools@57.5.0
65.5.1

Open the chart page →

1,636

Container images carrying it

786 by charts deploying them

A fixed version is listed for 14 of the 14 affected packages.

Container imageDigestPackageFixed inUsed by
andrianrf/backoffice:latest047a7837651e
setuptools@39.2.0
65.5.1
1
apache/airflow:2.8.4-python3.964e58748b6b9
setuptools@58.1.0
65.5.1
1
apache/airflow:2.10.2-python3.9ce90bdc3d2af
setuptools@58.1.0
65.5.1
1
apache/airflow:2.8.1e5560ad0b86e
setuptools@57.5.0
65.5.1
1
apache/bookkeeper:4.14.5a7d9970c148f
setuptools@39.2.0
65.5.1
1
apache/hadoop:3af361b20bec0
setuptools@0.9.8
65.5.1
1
apachepulsar/pulsar:3.1.016f9fdab3fa6
setuptools@59.6.0
65.5.1
1
apachepulsar/pulsar:2.10.03b262ab7a7d9
setuptools@45.2.0
python-pip@20.0.2-5ubuntu1.6
setuptools@45.2.0-1
65.5.1
20.0.2-5ubuntu1.7
45.2.0-1ubuntu0.1
1
apachepulsar/pulsar:2.6.14db6ff0b4045
setuptools@40.8.0
65.5.1
1
apachepulsar/pulsar:3.0.79c9947de139d
setuptools@59.6.0
65.5.1
1
apachepulsar/pulsar:2.9.0d056c89b7131
setuptools@45.2.0
setuptools@45.2.0-1
65.5.1
45.2.0-1ubuntu0.1
1
apachepulsar/pulsar:2.8.2d538416d5afe
setuptools@45.2.0
setuptools@45.2.0-1
65.5.1
45.2.0-1ubuntu0.1
1
apache/ranger:2.7.076c176e8a0e4
setuptools@59.6.0
65.5.1
1
apache/superset:9cdaa280429ec297db16d56c94fd77b5d2aff107975ab033580d
setuptools@57.5.0
65.5.1
1
apache/superset:4.0.1ab9467fd712c
setuptools@58.1.0
65.5.1
1
apecloud/kb-cloud-installer:v2.1.42-certified98abc64aa985
setuptools@53.0.0
65.5.1
1
apecloud/smartfs-csi-driver:0.1.1ff2858eab9cc
setuptools@39.2.0
python-chardet@3.0.4-7.el8
python-idna@2.5-5.el8
python-pysocks@1.6.8-3.el8
python-requests@2.20.0-3.el8_8
python-urllib3@1.24.2-5.el8
65.5.1
0:3.0.4-19.module+el8.4.0+9822+20bf1249
0:2.10-3.module+el8.4.0+9822+20bf1249
0:1.7.1-4.module+el8.4.0+9822+20bf1249
0:2.25.0-2.module+el8.4.0+9822+20bf1249
0:1.25.10-4.module+el8.5.0+11712+ea2d2be1
1
apicurio/apicurio-registry-kafkasql:2.1.0.Finala97d67487532
setuptools@39.2.0
python-setuptools@39.2.0-6.el8
65.5.1
0:39.2.0-6.el8_7.1
1
apicurio/apicurio-studio-api:0.2.62.Final302d202ed149
setuptools@39.2.0
65.5.1
1
apicurio/apicurio-studio-ui:0.2.62.Final349c845270c2
setuptools@39.2.0
65.5.1
1
apicurio/apicurio-studio-ws:0.2.62.Final27a91978a388
setuptools@39.2.0
65.5.1
1
applariat/tx-smtp-relay:latest6bc9655d920f
setuptools@20.8.0
65.5.1
1
apsl/thumbor:6.7.051e2de5c2c70
setuptools@41.6.0
65.5.1
1
aquasec/kube-hunter:1950bf607ce9308
setuptools@40.6.2
65.5.1
1
archish27/python-fastapi-postgres:latest6610071a2101
setuptools@58.1.0
65.5.1
1
asdkant/fastapi-hello-world:latesta23d8bf7c885
setuptools@51.0.0
65.5.1
1
assistiot/authorization_db:latestc3adbab6a3e7
setuptools@50.3.2
65.5.1
1
assistiot/cybersecurity-monitoring_id-elk:latestba1d85ec3739
setuptools@0.9.8
65.5.1
1
assistiot/cybersecurity-monitoring_id-wzh:latest0aacefac9677
setuptools@46.1.3
65.5.1
1
assistiot/cybersecurity-monitoring_ir-elk:latest4228b7a8ef40
setuptools@39.2.0
65.5.1
1
assistiot/cybersecurity-monitoring_ir-kbn:latest0570b27bb7c2
setuptools@39.2.0
65.5.1
1
assistiot/fl_repository:latest0fce3ea719a5
setuptools@47.1.1
65.5.1
1
assistiot/fl_training_collector:latest792715dd3084
setuptools@47.1.1
65.5.1
1
assistiot/identity-manager_kc:latest0df4b4fa899a
setuptools@39.2.0
python-setuptools@39.2.0-6.el8
65.5.1
0:39.2.0-6.el8_7.1
1
assistiot/open_api_backend:1.1.230812ba93555
setuptools@59.6.0
65.5.1
1
assistiot/resource-provisioning_api:1.0.044a37b00d4f8
setuptools@57.5.0
65.5.1
1
assistiot/resource-provisioning_im:1.0.0a942dc14030a
setuptools@57.5.0
65.5.1
1
assistiot/resource-provisioning_prc:1.0.08b5d118bdf0e
setuptools@57.5.0
65.5.1
1
assistiot/smart-orchestrator_mcs:latest7d6a0d534c7f
setuptools@57.5.0
65.5.1
1
assistiot/smart-orchestrator_scheduler:latest38b003e55ff3
setuptools@57.5.0
65.5.1
1
assistiot/smart-orchestrator_scheduler_mc:latestb1dbe4d62a03
setuptools@57.5.0
65.5.1
1
assistiot/traffic-classification_api:2.0.0e32b87786142
setuptools@57.5.0
65.5.1
1
atlassian/confluence-server:7.10.03b9222ab32ef
setuptools@59.6.0-1.2
59.6.0-1.2ubuntu0.22.04.1
1
avinash263/pyredis263:latestaa2b8727f1a6
setuptools@57.5.0
65.5.1
1
azhar008/flaskapplication:latesta1e827b0adea
setuptools@57.5.0
65.5.1
1
badsmoke/wunderground_exporter:0.0.5c54c004f24cc
setuptools@53.0.0
65.5.1
1
balihb/block-pvc-scanner:0.2.45b95e1cf1158
setuptools@57.5.0
65.5.1
1
balihb/pod-pvc-mapping:0.2.4ee48e79f5d76
setuptools@57.5.0
65.5.1
1
bbernhard/signal-cli-rest-api:0.57549ad08d7e14
setuptools@45.2.0-1
45.2.0-1ubuntu0.1
1
bbvalabs/sensitive-data:1.0.13ea299ae63c0
setuptools@56.0.0
65.5.1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.