pypa/setuptools on GitHub
Official project repository for the Setuptools build system
CVE History
CVE | Published | CVSS v2 | CVSS v3 |
---|---|---|---|
CVE-2022-40897 | 5.9 MEDIUM | N/A | |
Python Packaging Authority (PyPA) setuptools before 65.5.1 allows remote attackers to cause a denial of service via HTML in a crafted package or custom PackageIndex page. There is a Regular Expression Denial of Service (ReDoS) in package_index.py. |