### [CVE-2022-40897](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-40897) ![](https://img.shields.io/static/v1?label=Product&message=n%2Fa&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue) ![](https://img.shields.io/static/v1?label=Vulnerability&message=n%2Fa&color=brighgreen) ### Description Python Packaging Authority (PyPA) setuptools before 65.5.1 allows remote attackers to cause a denial of service via HTML in a crafted package or custom PackageIndex page. There is a Regular Expression Denial of Service (ReDoS) in package_index.py. ### POC #### Reference - https://pyup.io/posts/pyup-discovers-redos-vulnerabilities-in-top-python-packages/ #### Github - https://github.com/ARPSyndicate/cvemon - https://github.com/Fred090821/devops - https://github.com/Fred090821/devopsdocker - https://github.com/GitHubForSnap/matrix-commander-gael - https://github.com/SenhorDosSonhos1/projeto-voluntario-lacrei - https://github.com/Viselabs/zammad-google-cloud-docker - https://github.com/efrei-ADDA84/20200511 - https://github.com/fredrkl/trivy-demo - https://github.com/jbugeja/test-repo - https://github.com/mansi1811-s/samp - https://github.com/seal-community/patches