setuptools@60.6.0 vulnerabilities

Easily download, build, install, upgrade, and uninstall Python packages

Direct Vulnerabilities

Known vulnerabilities in the setuptools package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • M
Regular Expression Denial of Service (ReDoS)

Affected versions of this package are vulnerable to Regular Expression Denial of Service (ReDoS) via crafted HTML package or custom PackageIndex page.

Note:

Only a small portion of the user base is impacted by this flaw. Setuptools maintainers pointed out that package_index is deprecated (not formally, but “in spirit”) and the vulnerability isn't reachable through standard, recommended workflows.

How to fix Regular Expression Denial of Service (ReDoS)?

Upgrade setuptools to version 65.5.1 or higher.

[,65.5.1)