Root has patched CVE-2022-40898 in the rootio-wheel package for Root:PyPI. Multiple fixed versions available.
{ "distro": "pypi", "source": "Root", "distro_version": "" }
2.0
"https://api.root.io/external/osv/ROOT-APP-PYPI-CVE-2022-40898.json"
"root.io.1"
[ "0.37.1+root.io.1", "0.37.0+root.io.1" ]
true
"0.37.0"