StackRadar

CVE-2022-40897

High

Advisory

Published 23 Dec 2022In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.026
85th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
765
of 17,787 indexed, latest versions
Container images
794
deployed by those charts
Fix available
14 of 14
affected packages

pypa/setuptools vulnerable to Regular Expression Denial of Service (ReDoS)

Carried by container images the latest versions of 765 of 17,787 indexed charts deploy, on 794 images.

Affected packageAffected versionsFixed inImages
setuptoolspypi0.9.8, 20.7.0, 20.8.0, 29.0.1.post20161130+84 more65.5.1763
python-setuptoolsrpm39.2.0-5.el8, 39.2.0-6.el80:39.2.0-6.el8_7.162
setuptoolsdeb45.2.0-1, 59.6.0-1.245.2.0-1ubuntu0.1, 59.6.0-1.2ubuntu0.22.04.153
python-pipdeb1.5.4-1ubuntu4, 8.1.1-2ubuntu0.4, 9.0.1-2.3~ubuntu1, 9.0.1-2.3~ubuntu1.18.04.1+7 more1.5.4-1ubuntu4+esm2, 8.1.1-2ubuntu0.6+esm3, 9.0.1-2.3~ubuntu1.18.04.6, 20.0.2-5ubuntu1.7+1 more52
python-setuptoolsdeb3.3-1ubuntu1, 3.3-1ubuntu2, 20.7.0-1, 39.0.1-2+1 more3.3-1ubuntu2+esm1, 20.7.0-1ubuntu0.1~esm1, 39.0.1-2ubuntu0.1, 44.0.0-2ubuntu0.134
python3x-setuptoolsrpm41.6.0-5.module+el8.5.0+12205+a865257a, 50.3.2-4.module+el8.5.0+12204+548604230:50.3.2-5.module+el8.8.0+21635+a173a6fa6
python39rpm3.9.16-1.module+el8.8.0+18968+3d7b19f0.10:3.9.16-1.module+el8.8.0+20025+f2100191.25
python-chardetrpm3.0.4-7.el80:3.0.4-19.module+el8.4.0+9822+20bf12493
python-idnarpm2.5-5.el80:2.10-3.module+el8.4.0+9822+20bf12493
python-pysocksrpm1.6.8-3.el80:1.7.1-4.module+el8.4.0+9822+20bf12493
python-requestsrpm2.20.0-2.1.el8_1, 2.20.0-3.el8_80:2.25.0-2.module+el8.4.0+9822+20bf12493
python-urllib3rpm1.24.2-5.el80:1.25.10-4.module+el8.5.0+11712+ea2d2be13
python3x-piprpm19.3.1-6.module+el8.7.0+15823+8950cfa70:20.2.4-7.module+el8.6.0+13003+6bb2c4881
python-plyrpm3.9-9.el80:3.11-10.module+el8.4.0+9822+20bf12491
OSV records
GHSA-r9hx-vwmv-q579RHSA-2023:0835RHSA-2024:4421UBUNTU-CVE-2022-40897
Also known as
BIT-setuptools-2022-40897, PYSEC-2022-43012, RHSA-2023:7395, USN-5817-1

Charts affected

765 by stars
ChartLatestAffected imagesRadar Score
minio-standalonewenerme1.0.21 of 1See more

minio-standalone wenerme 1.0.2

1 of the 1 container images this version deploys carry CVE-2022-40897.

Container imageDigestPackageFixed in
minio/minio:RELEASE.2022-01-04T07-41-07Z1484c87239ea
setuptools@39.2.0
python-setuptools@39.2.0-6.el8
65.5.1
0:39.2.0-6.el8_7.1

Open the chart page →

6,138
sambawenerme1.0.01 of 1See more

samba wenerme 1.0.0

1 of the 1 container images this version deploys carry CVE-2022-40897.

Container imageDigestPackageFixed in
wener/samba:4.13.39a42bae466d4
setuptools@51.3.3
65.5.1

Open the chart page →

2,555
temporalwenerme0.15.11 of 13See more

temporal wenerme 0.15.1

1 of the 13 container images this version deploys carry CVE-2022-40897.

Container imageDigestPackageFixed in
temporalio/admin-tools:1.15.135034611d981
setuptools@44.1.1
65.5.1

Open the chart page →

22,665
ceph-csi-cephfswikimedia0.1.81 of 5See more

ceph-csi-cephfs wikimedia 0.1.8

1 of the 5 container images this version deploys carry CVE-2022-40897.

Container imageDigestPackageFixed in
quay.io/cephcsi/cephcsi:v3.7.2f7f8228f17cc
setuptools@39.2.0
65.5.1

Open the chart page →

10,285
ceph-csi-rbdwikimedia0.1.131 of 6See more

ceph-csi-rbd wikimedia 0.1.13

1 of the 6 container images this version deploys carry CVE-2022-40897.

Container imageDigestPackageFixed in
quay.io/cephcsi/cephcsi:v3.7.2f7f8228f17cc
setuptools@39.2.0
65.5.1

Open the chart page →

11,784
docker-hub-rate-limit-exporterwiremindVerified publisher0.3.01 of 1See more

docker-hub-rate-limit-exporter wiremind 0.3.0

1 of the 1 container images this version deploys carry CVE-2022-40897.

Container imageDigestPackageFixed in
viadee/docker-hub-rate-limit-exporter:version-1.52e27e3b3ee56
setuptools@52.0.0
65.5.1

Open the chart page →

1,843
pypiwiremindVerified publisher0.2.11 of 1See more

pypi wiremind 0.2.1

1 of the 1 container images this version deploys carry CVE-2022-40897.

Container imageDigestPackageFixed in
codekoala/pypi:1.2.14a999b2cfff2
setuptools@29.0.1.post20161130
65.5.1

Open the chart page →

423
opendistro-eswitcom-gmbh1.13.31 of 3See more

opendistro-es witcom-gmbh 1.13.3

1 of the 3 container images this version deploys carry CVE-2022-40897.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch:1.13.32acfa1dcc5f8
setuptools@0.9.8
65.5.1

Open the chart page →

5,806
powerdnsadminwitcom-gmbh0.3.41 of 1See more

powerdnsadmin witcom-gmbh 0.3.4

1 of the 1 container images this version deploys carry CVE-2022-40897.

Container imageDigestPackageFixed in
ngoduykhanh/powerdns-admin:v0.2.4ba36ab196d3d
setuptools@51.3.3
65.5.1

Open the chart page →

2,643
workshop-pipelinesworkshop-pipelines0.1.61 of 2See more

workshop-pipelines workshop-pipelines 0.1.6

1 of the 2 container images this version deploys carry CVE-2022-40897.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/workshop-pipelines:lateste383ba3e0966
setuptools@39.2.0
python-setuptools@39.2.0-6.el8
65.5.1
0:39.2.0-6.el8_7.1

Open the chart page →

11,577
xkopsxkops0.1.02 of 5See more

xkops xkops 0.1.0

2 of the 5 container images this version deploys carry CVE-2022-40897.

Container imageDigestPackageFixed in
hamzaarshad10/querybackend:1.6.22c1c3b86a8e7
setuptools@58.1.0
65.5.1
murtazashah46/helmfile:latest4d11726cf803
setuptools@58.1.0
65.5.1

Open the chart page →

13,677
keycloakxzaks2.2.01 of 1See more

keycloakx zaks 2.2.0

1 of the 1 container images this version deploys carry CVE-2022-40897.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0.3b8f2a453a17a
setuptools@39.2.0
python-setuptools@39.2.0-6.el8
65.5.1
0:39.2.0-6.el8_7.1

Open the chart page →

6,016
sockpuppetbrowserzekker6Verified publisher0.1.01 of 1See more

sockpuppetbrowser zekker6 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-40897.

Container imageDigestPackageFixed in
dgtlmoon/sockpuppetbrowser:latestf166a963b550
setuptools@65.5.0
65.5.1

Open the chart page →

1,589
alertmanager-matrix-forwarderzloi-space1.0.11 of 2See more

alertmanager-matrix-forwarder zloi-space 1.0.1

1 of the 2 container images this version deploys carry CVE-2022-40897.

Container imageDigestPackageFixed in
matrixdotorg/pantalaimon:v0.10.4ba6a587fa508
setuptools@57.5.0
65.5.1

Open the chart page →

3,118
grafana-matrix-forwarderzloi-space1.0.01 of 2See more

grafana-matrix-forwarder zloi-space 1.0.0

1 of the 2 container images this version deploys carry CVE-2022-40897.

Container imageDigestPackageFixed in
matrixdotorg/pantalaimon:v0.10.4ba6a587fa508
setuptools@57.5.0
65.5.1

Open the chart page →

1,636

Container images carrying it

794 by charts deploying them

A fixed version is listed for 14 of the 14 affected packages.

Container imageDigestPackageFixed inUsed by
erlangsolutions/wombatoam:4.1.284680c990147a
setuptools@52.0.0
65.5.1
1
errbotio/errbot:6.1.900ee4e0953ab
setuptools@60.5.0
65.5.1
1
esailors/aws-ecr-http-proxy:1.5.15608ae045fa7
setuptools@52.0.0
65.5.1
1
esphome/esphome:1.18.03f51ec10e823
setuptools@40.8.0
65.5.1
1
ethereumex/eth-stats-dashboard:v0.0.1a7603aa8df4c
python-setuptools@20.7.0-1
20.7.0-1ubuntu0.1~esm1
1
evk02/mlflow:2.2.1ef6ff257ef35
setuptools@57.5.0
65.5.1
1
factly/hunting:0.2.0-stagv1.2ca5bc71d1d5c
setuptools@58.1.0
65.5.1
1
fiware/bae-activation-service:v0.0.33e3ec88d59ed
setuptools@39.2.0
65.5.1
1
fiware/biz-ecosystem-charging-backend:11.7.029456835bb2c
setuptools@45.2.0
65.5.1
1
fiware/ishare-satellite:1.2.0c3c1c8ccfb45
setuptools@57.5.0
65.5.1
1
fiware/mintaka:0.7.092a3c5cf43c0
setuptools@39.2.0
python-setuptools@39.2.0-6.el8
65.5.1
0:39.2.0-6.el8_7.1
1
fiware/mintaka:latestefc6793388cc
setuptools@39.2.0
python-setuptools@39.2.0-6.el8
65.5.1
0:39.2.0-6.el8_7.1
1
fiware/orion-ld:1.10.03c490a746f65
setuptools@39.2.0
65.5.1
1
flag5/clustersecret:0.0.94ad5748bfcc6
setuptools@57.5.0
65.5.1
1
flagsmith/flagsmith-api:v2.6.0fd58556339a4
setuptools@54.2.0
65.5.1
1
flyway/flyway:9.1545b5d7cdc75a
setuptools@45.2.0
65.5.1
1
forchaladtest/testwebapp:0.15909cf64ef53
setuptools@44.1.0
65.5.1
1
foundationdb/foundationdb-kubernetes-sidecar:6.3.23-107e0ae17a7ca
setuptools@41.6.0
65.5.1
1
foundationdb/foundationdb-kubernetes-sidecar:6.2.30-19ceb2f948c9f
setuptools@53.0.0
65.5.1
1
foundationdb/foundationdb-kubernetes-sidecar:7.1.38-1da1ee2731024
setuptools@41.6.0
65.5.1
1
frankescobar/allure-docker-service:2.21.08a4d7e9308de
setuptools@47.1.1
65.5.1
1
frankescobar/allure-docker-service:2.19.0cafa03b94dac
setuptools@47.1.1
python-pip@9.0.1-2.3~ubuntu1.18.04.5
65.5.1
9.0.1-2.3~ubuntu1.18.04.6
1
freedom98/flask:k3.0d7ce1533f297
setuptools@53.0.0
65.5.1
1
freeipa/freeipa-server:fedora-37-4.10.1c87d77342bf5
setuptools@62.6.0
65.5.1
1
gabibbo97/389ds:fedora-32c047ea64e8cb
setuptools@41.6.0
65.5.1
1
galaxy/cloudman-server:lateste5c265fe9fcd
setuptools@45.2.0
python-pip@20.0.2-5ubuntu1.6
setuptools@45.2.0-1
65.5.1
20.0.2-5ubuntu1.7
45.2.0-1ubuntu0.1
1
galaxy/galaxy-init:v18.010267bad550e6
setuptools@36.5.0.post20170921
python-pip@1.5.4-1ubuntu4
python-setuptools@3.3-1ubuntu2
65.5.1
1.5.4-1ubuntu4+esm2
3.3-1ubuntu2+esm1
1
galaxy/galaxy-stable:v18.018e577a626dfd
setuptools@39.2.0
python-pip@1.5.4-1ubuntu4
python-setuptools@3.3-1ubuntu2
65.5.1
1.5.4-1ubuntu4+esm2
3.3-1ubuntu2+esm1
1
geonode/geoserver:2.28.4-latest81b1d431b7e9
setuptools@59.6.0
65.5.1
1
geoscienceaustralia/dea-k8s-data:latestf4039b45572a
setuptools@50.3.0
python-pip@9.0.1-2.3~ubuntu1.18.04.2
65.5.1
9.0.1-2.3~ubuntu1.18.04.6
1
gethue/hue:4.11.011b649636e68
setuptools@65.3.0
python-pip@20.0.2-5ubuntu1.6
setuptools@45.2.0-1
65.5.1
20.0.2-5ubuntu1.7
45.2.0-1ubuntu0.1
1
gethue/hue:4.10.05702b2c37ff9
setuptools@39.0.1
python-pip@9.0.1-2.3~ubuntu1.18.04.5
python-setuptools@39.0.1-2
65.5.1
9.0.1-2.3~ubuntu1.18.04.6
39.0.1-2ubuntu0.1
1
gethue/hue:latest7d5c1b9f8a79
setuptools@59.6.0
65.5.1
1
getsentry/sentry-kubernetes:latest6ac37974fd2a
setuptools@40.8.0
65.5.1
1
gluufederation/opendj:4.3.0_011a1128b28b95
setuptools@52.0.0
65.5.1
1
gmelillo/registry:0.1.8c599d608a2f7
setuptools@52.0.0
65.5.1
1
gomods/athens:v0.8.1d714c7ff0231
setuptools@41.2.0
65.5.1
1
gomods/athens:v0.11.0efb811df7844
setuptools@41.2.0
65.5.1
1
goofball222/pritunl:1.30.3070.5943c0743701d4
setuptools@52.0.0
65.5.1
1
goofball222/pritunl:1.32.3602.807bf26032dfce
setuptools@59.4.0
65.5.1
1
graphiteapp/graphite-statsd:1.1.7-604a0037cc2ae
setuptools@49.2.0
65.5.1
1
greenbirdit/locust:0.9.0e99d53bdc944
setuptools@40.6.3
65.5.1
1
gristlabs/grist:0.7.96e71b1914a7e
setuptools@40.8.0
65.5.1
1
gurolakman/oam:4.0.0ed8fd2062548
setuptools@39.2.0
65.5.1
1
gurolakman/smsf-configuration:1.0.49abb3882bcbd
setuptools@39.2.0
65.5.1
1
gurolakman/smsf-dispatcher:1.0.46537e8ed8de8
setuptools@39.2.0
65.5.1
1
gurolakman/smsf-momt:1.0.4ce23b20a8a17
setuptools@39.2.0
65.5.1
1
gurolakman/smsf-registration:1.0.4b22e746edd5d
setuptools@39.2.0
65.5.1
1
gurolakman/ussigw-configuration:1.0.4bf18525c5ad9
setuptools@39.2.0
65.5.1
1
gurolakman/ussigw-core:1.0.48739565c3ea2
setuptools@39.2.0
65.5.1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.