Skip to main content

Vendor/product archive

python / setuptools CVEs

Beta · best-effort

4 CVEs tagged to python / setuptools0 Critical, 1 High, 3 Medium, 0 Low, 0 Unrated.

CVE-2026-59890

Published Jul 8, 2026

setuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. Prior to 83.0.0, FileList applied MANIFEST.in exclude, global-exclud…

CVSS 6.1 · Medium
evidence mentions
4
Buzz score
26.1
Vendor/product tagsBeta · best-effort

CVE-2025-47273

Published May 17, 2025

setuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. A path traversal vulnerability in `PackageIndex` is present in setup…

CVSS 7.7 · High
Vendor/product tagsBeta · best-effort

CVE-2022-40897

Published Dec 23, 2022

Python Packaging Authority (PyPA) setuptools before 65.5.1 allows remote attackers to cause a denial of service via HTML in a crafted package or custom PackageIndex page. There is…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-1633

Published Aug 6, 2013

easy_install in setuptools before 0.7 uses HTTP to retrieve packages from the PyPI repository, and does not perform integrity checks on package contents, which allows man-in-the-m…

CVSS 6.8 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 1-4 of 4 CVEsPage 1 of 1