Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
Vulnerabilities
search
All ecosystems
615431
AlmaLinux
4641
Alpaquita
8784
Alpine
4048
Android
3261
BellSoft Hardened Containers
428
Bitnami
6958
Chainguard
5676
CleanStart
757
CRAN
14
crates.io
2213
Debian
54248
Echo
3171
GHC
3
GIT
81471
GitHub Actions
49
Go
6547
Hackage
30
Hex
57
Julia
483
Linux
15361
Mageia
5874
Maven
6322
MinimOS
26477
npm
217329
NuGet
1657
opam
12
openEuler
6386
openSUSE
12470
OSS-Fuzz
3826
Packagist
6068
Pub
11
PyPI
18672
Red Hat
19215
Rocky Linux
2938
Root
11916
RubyGems
1933
SUSE
20373
SwiftURL
50
Ubuntu
52049
VSCode
18
Wolfi
3635
ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-5rjg-fvgr-3xxf
PyPI/setuptools
setuptools has a path traversal vulnerability in PackageIndex.download that leads to Arbitrary File Write
19 May 2025
Fix available
Severity - 7.7 (High)
PYSEC-2025-49
PyPI/setuptools
github.com/pypa/setuptools
See record for full details
17 May 2025
Fix available
Severity - 8.8 (High)
GHSA-cx63-2mw6-8hw5
PyPI/setuptools
setuptools vulnerable to Command Injection via package URL
15 Jul 2024
Fix available
Severity - 7.5 (High)
GHSA-r9hx-vwmv-q579
PyPI/setuptools
pypa/setuptools vulnerable to Regular Expression Denial of Service (ReDoS)
23 Dec 2022
Fix available
Severity - 8.7 (High)
PYSEC-2022-43012
PyPI/setuptools
github.com/pypa/setuptools
See record for full details
23 Dec 2022
Fix available
GHSA-27x4-j476-jp5f
PyPI/setuptools
Setuptools vulnerable to Man-in-the-middle attacks
17 May 2022
Fix available
Severity - 8.3 (High)
PYSEC-2013-22
PyPI/setuptools
See record for full details
06 Aug 2013
Fix available
PyPI - OSV