StackRadar

CVE-2022-40897

High

Advisory

Published 23 Dec 2022In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.026
85th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
762
of 17,787 indexed, latest versions
Container images
791
deployed by those charts
Fix available
14 of 14
affected packages

pypa/setuptools vulnerable to Regular Expression Denial of Service (ReDoS)

Carried by container images the latest versions of 762 of 17,787 indexed charts deploy, on 791 images.

Affected packageAffected versionsFixed inImages
setuptoolspypi0.9.8, 20.7.0, 20.8.0, 29.0.1.post20161130+84 more65.5.1760
python-setuptoolsrpm39.2.0-5.el8, 39.2.0-6.el80:39.2.0-6.el8_7.162
setuptoolsdeb45.2.0-1, 59.6.0-1.245.2.0-1ubuntu0.1, 59.6.0-1.2ubuntu0.22.04.153
python-pipdeb1.5.4-1ubuntu4, 8.1.1-2ubuntu0.4, 9.0.1-2.3~ubuntu1, 9.0.1-2.3~ubuntu1.18.04.1+7 more1.5.4-1ubuntu4+esm2, 8.1.1-2ubuntu0.6+esm3, 9.0.1-2.3~ubuntu1.18.04.6, 20.0.2-5ubuntu1.7+1 more52
python-setuptoolsdeb3.3-1ubuntu1, 3.3-1ubuntu2, 20.7.0-1, 39.0.1-2+1 more3.3-1ubuntu2+esm1, 20.7.0-1ubuntu0.1~esm1, 39.0.1-2ubuntu0.1, 44.0.0-2ubuntu0.134
python3x-setuptoolsrpm41.6.0-5.module+el8.5.0+12205+a865257a, 50.3.2-4.module+el8.5.0+12204+548604230:50.3.2-5.module+el8.8.0+21635+a173a6fa6
python39rpm3.9.16-1.module+el8.8.0+18968+3d7b19f0.10:3.9.16-1.module+el8.8.0+20025+f2100191.25
python-chardetrpm3.0.4-7.el80:3.0.4-19.module+el8.4.0+9822+20bf12493
python-idnarpm2.5-5.el80:2.10-3.module+el8.4.0+9822+20bf12493
python-pysocksrpm1.6.8-3.el80:1.7.1-4.module+el8.4.0+9822+20bf12493
python-requestsrpm2.20.0-2.1.el8_1, 2.20.0-3.el8_80:2.25.0-2.module+el8.4.0+9822+20bf12493
python-urllib3rpm1.24.2-5.el80:1.25.10-4.module+el8.5.0+11712+ea2d2be13
python3x-piprpm19.3.1-6.module+el8.7.0+15823+8950cfa70:20.2.4-7.module+el8.6.0+13003+6bb2c4881
python-plyrpm3.9-9.el80:3.11-10.module+el8.4.0+9822+20bf12491
OSV records
GHSA-r9hx-vwmv-q579RHSA-2023:0835RHSA-2024:4421UBUNTU-CVE-2022-40897
Also known as
BIT-setuptools-2022-40897, PYSEC-2022-43012, RHSA-2023:7395, USN-5817-1

Charts affected

762 by stars
ChartLatestAffected imagesRadar Score
ceph-csi-cephfswikimedia0.1.81 of 5See more

ceph-csi-cephfs wikimedia 0.1.8

1 of the 5 container images this version deploys carry CVE-2022-40897.

Container imageDigestPackageFixed in
quay.io/cephcsi/cephcsi:v3.7.2f7f8228f17cc
setuptools@39.2.0
65.5.1

Open the chart page →

10,285
ceph-csi-rbdwikimedia0.1.131 of 6See more

ceph-csi-rbd wikimedia 0.1.13

1 of the 6 container images this version deploys carry CVE-2022-40897.

Container imageDigestPackageFixed in
quay.io/cephcsi/cephcsi:v3.7.2f7f8228f17cc
setuptools@39.2.0
65.5.1

Open the chart page →

11,784
docker-hub-rate-limit-exporterwiremindVerified publisher0.3.01 of 1See more

docker-hub-rate-limit-exporter wiremind 0.3.0

1 of the 1 container images this version deploys carry CVE-2022-40897.

Container imageDigestPackageFixed in
viadee/docker-hub-rate-limit-exporter:version-1.52e27e3b3ee56
setuptools@52.0.0
65.5.1

Open the chart page →

1,843
pypiwiremindVerified publisher0.2.11 of 1See more

pypi wiremind 0.2.1

1 of the 1 container images this version deploys carry CVE-2022-40897.

Container imageDigestPackageFixed in
codekoala/pypi:1.2.14a999b2cfff2
setuptools@29.0.1.post20161130
65.5.1

Open the chart page →

423
opendistro-eswitcom-gmbh1.13.31 of 3See more

opendistro-es witcom-gmbh 1.13.3

1 of the 3 container images this version deploys carry CVE-2022-40897.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch:1.13.32acfa1dcc5f8
setuptools@0.9.8
65.5.1

Open the chart page →

5,806
powerdnsadminwitcom-gmbh0.3.41 of 1See more

powerdnsadmin witcom-gmbh 0.3.4

1 of the 1 container images this version deploys carry CVE-2022-40897.

Container imageDigestPackageFixed in
ngoduykhanh/powerdns-admin:v0.2.4ba36ab196d3d
setuptools@51.3.3
65.5.1

Open the chart page →

2,643
workshop-pipelinesworkshop-pipelines0.1.61 of 2See more

workshop-pipelines workshop-pipelines 0.1.6

1 of the 2 container images this version deploys carry CVE-2022-40897.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/workshop-pipelines:lateste383ba3e0966
setuptools@39.2.0
python-setuptools@39.2.0-6.el8
65.5.1
0:39.2.0-6.el8_7.1

Open the chart page →

11,577
xkopsxkops0.1.02 of 5See more

xkops xkops 0.1.0

2 of the 5 container images this version deploys carry CVE-2022-40897.

Container imageDigestPackageFixed in
hamzaarshad10/querybackend:1.6.22c1c3b86a8e7
setuptools@58.1.0
65.5.1
murtazashah46/helmfile:latest4d11726cf803
setuptools@58.1.0
65.5.1

Open the chart page →

13,677
keycloakxzaks2.2.01 of 1See more

keycloakx zaks 2.2.0

1 of the 1 container images this version deploys carry CVE-2022-40897.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0.3b8f2a453a17a
setuptools@39.2.0
python-setuptools@39.2.0-6.el8
65.5.1
0:39.2.0-6.el8_7.1

Open the chart page →

6,016
sockpuppetbrowserzekker6Verified publisher0.1.01 of 1See more

sockpuppetbrowser zekker6 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-40897.

Container imageDigestPackageFixed in
dgtlmoon/sockpuppetbrowser:latestf166a963b550
setuptools@65.5.0
65.5.1

Open the chart page →

1,589
alertmanager-matrix-forwarderzloi-space1.0.11 of 2See more

alertmanager-matrix-forwarder zloi-space 1.0.1

1 of the 2 container images this version deploys carry CVE-2022-40897.

Container imageDigestPackageFixed in
matrixdotorg/pantalaimon:v0.10.4ba6a587fa508
setuptools@57.5.0
65.5.1

Open the chart page →

3,118
grafana-matrix-forwarderzloi-space1.0.01 of 2See more

grafana-matrix-forwarder zloi-space 1.0.0

1 of the 2 container images this version deploys carry CVE-2022-40897.

Container imageDigestPackageFixed in
matrixdotorg/pantalaimon:v0.10.4ba6a587fa508
setuptools@57.5.0
65.5.1

Open the chart page →

1,636

Container images carrying it

791 by charts deploying them

A fixed version is listed for 14 of the 14 affected packages.

Container imageDigestPackageFixed inUsed by
linuxserver/healthchecks:2.7.2023033194696dab3c50
setuptools@65.5.0
65.5.1
1
linuxserver/medusa:v0.3.9-ls340a5f5114128b
setuptools@41.2.0
65.5.1
1
linuxserver/sickchill:v2020.08.07-1-ls40e48b479c1891
setuptools@42.0.2.post20191202
65.5.1
1
linuxserver/yq:3.2.26f5b9586a93e
setuptools@65.5.0
65.5.1
1
lnbitsdocker/lnbits-legend:latest26fae6327477
setuptools@65.5.0
65.5.1
1
lnbitsdocker/lnbits-legend:0.10.6a11aaa6d2b21
setuptools@65.5.0
65.5.1
1
lncm/specter-desktop:v0.10.4bca14d04397d
setuptools@50.3.0
65.5.1
1
locustio/locust:2.24.151d866285170
setuptools@65.5.0
65.5.1
1
logiqai/toolbox:2.0.155a574ec5b64
setuptools@42.0.2.post20191202
65.5.1
1
lsstdm/alert-stream-simulator:v1.2.1973df082d006
setuptools@57.5.0
65.5.1
1
lsstdm/lsst_alert_packet:tickets-DM-3274374c97a490940
setuptools@57.5.0
65.5.1
1
lsstsqre/exposurelog:0.8.079b00fb67a65
setuptools@60.8.2
65.5.1
1
lsstsqre/kafkaaggregator:masterbe1b21060854
setuptools@54.1.2
65.5.1
1
lsstsqre/kafkaconnect:0.9.34143c7cd705e
setuptools@57.5.0
65.5.1
1
lsstsqre/narrativelog:0.1.0ce01de04ce21
setuptools@60.9.1
65.5.1
1
lsstsqre/nublado2:2.0.1b75bf8aaafa4
setuptools@60.5.0
python-pip@20.0.2-5ubuntu1.6
python-setuptools@44.0.0-2
setuptools@45.2.0-1
65.5.1
20.0.2-5ubuntu1.7
44.0.0-2ubuntu0.1
45.2.0-1ubuntu0.1
1
lsstsqre/prepuller:latest19c2dfc4e4ff
setuptools@56.0.0
65.5.1
1
lsstsqre/sciplat-hub:latest5e0ade6bed1c
setuptools@0.9.8
65.5.1
1
lsstsqre/squash-api:0.5.34879415ec6ac
setuptools@51.0.0
65.5.1
1
lsstsqre/strimzi-registry-operator:0.4.1e139fde946d7
setuptools@57.5.0
65.5.1
1
lsstsqre/wfdispatcher:lateste9feb99f524d
setuptools@39.2.0
65.5.1
1
marcinkujawski/flask-app:2.0.1a455017b9d0e
setuptools@57.5.0
65.5.1
1
mariadb/maxscale:23.02.256c5e0908148
setuptools@39.2.0
65.5.1
1
matrixdotorg/synapse:v1.53.0cb89c0f17ba1
setuptools@57.5.0
65.5.1
1
mcronce/yadms-ftp:latestf820ef2e3c26
setuptools@41.6.0
65.5.1
1
mcronce/yadms-web:latestc03c1c7f5aa9
setuptools@41.6.0
65.5.1
1
mediagis/nominatim:3.7c15e941485ef
setuptools@45.2.0
python-pip@20.0.2-5ubuntu1.6
setuptools@45.2.0-1
65.5.1
20.0.2-5ubuntu1.7
45.2.0-1ubuntu0.1
1
mediagis/nominatim:4.2d0eae7b51374
setuptools@59.6.0
65.5.1
1
middlewareeng/middleware:0.3.1747d880812f1
setuptools@58.1.0
65.5.1
1
milesmcc/shynet:v0.12.0e821e31140f7
setuptools@57.5.0
65.5.1
1
miltex/python-api:1.0.0dab12a7748d5
setuptools@44.0.0
65.5.1
1
minio/minio:RELEASE.2022-01-04T07-41-07Z1484c87239ea
setuptools@39.2.0
python-setuptools@39.2.0-6.el8
65.5.1
0:39.2.0-6.el8_7.1
1
mintproject/data-catalog:9be70359feabe03ed55bfdbf92c20a7e43ab928b67d2f2103085
setuptools@57.5.0
65.5.1
1
mintproject/model-catalog-fastapi:7dd88dc5bf1fe6a6d4703ea0a077afee45cb256102260d20a21f
setuptools@65.5.0
65.5.1
1
mirrorgitlabcontainers/gitlab-sidekiq-ce:v13.2.294d1431683fa
setuptools@47.3.1
65.5.1
1
mirrorgitlabcontainers/gitlab-task-runner-ce:v13.2.29efd73993c34
setuptools@47.3.1
65.5.1
1
mirrorgitlabcontainers/gitlab-webservice-ce:v13.2.230393f990f5c
setuptools@47.3.1
65.5.1
1
mnaggar3396/python-app:latest371d8ed84b15
setuptools@58.1.0
65.5.1
1
mohameddev006/web-app:v50fbc7360ecf4
setuptools@57.5.0
65.5.1
1
moreillon/face-recognition-fastapi:x86bacb2ddd8394
setuptools@57.5.0
65.5.1
1
mozilla/syncserver:latest016162bf39d8
setuptools@44.1.0
65.5.1
1
mozilla/syncstorage-rs:0.15.893752877dced
setuptools@52.0.0
65.5.1
1
mshanley80/httpbin2022:latest5b189a70c0fb
setuptools@60.2.0
python-pip@20.0.2-5ubuntu1.6
setuptools@45.2.0-1
65.5.1
20.0.2-5ubuntu1.7
45.2.0-1ubuntu0.1
1
muluder/prograncontrollermcord:0.1.843b597a93da7
python-setuptools@20.7.0-1
20.7.0-1ubuntu0.1~esm1
1
murtazashah46/helmfile:latest4d11726cf803
setuptools@58.1.0
65.5.1
1
mvitale1989/docker-taiga:20191031-4.2.141504ccda06df
setuptools@41.4.0
65.5.1
1
mysql/mysql-cluster:8.0.20e4ea36622cdd
setuptools@40.8.0
65.5.1
1
nathanielvarona/pritunl-slack-app:0.1.10b746a34e5597
setuptools@63.2.0
65.5.1
1
neilpeterson/aks-helloworld:v1fb47732ef36b
setuptools@38.2.4
65.5.1
1
neilpeterson/chart-tweet:latest64fd8dab075f
setuptools@38.2.4
65.5.1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.