Remote Denial of Service in Setuptools by Python Packaging Authority
CVE-2022-40897
5.9MEDIUM
What is CVE-2022-40897?
A vulnerability exists in the setuptools package of the Python Packaging Authority that could allow remote attackers to induce a denial of service. This is achieved through the introduction of crafted HTML in a specially constructed package or custom PackageIndex page, which exploits a flaw in the regular expression implementation found within the package_index.py file. Attackers leveraging this weakness can effectively overwhelm the system, causing significant disruption.