VendorsPythonsetuptoolsall versions
Vulnerabilities

Python Setuptools

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2025-47273
setuptools has a path traversal vulnerability in PackageIndex.download that leads to Arbitrary File Write
Published 2025-05-17 · Analyzed
8.8EPSS 0.015
CVE-2013-1633
easy_install in setuptools before 0.7 uses HTTP to retrieve packages from the PyPI repository, and does not perform integrity checks on package contents, which allows man-in-the-middle attackers to execute arbitrary code via a crafted response to the default use of the product.
Published 2013-08-06 · Modified
6.8EPSS 0.020
CVE-2026-59890
setuptools: MANIFEST.in exclusion bypass in sdist via Unicode normalization collision (NFC/NFD) on macOS APFS/HFS+
Published 2026-07-08 · Analyzed
6.1EPSS 0.004
CVE-2022-40897
Python Packaging Authority (PyPA) setuptools before 65.5.1 allows remote attackers to cause a denial of service via HTML in a crafted package or custom PackageIndex page. There is a Regular Expression Denial of Service (ReDoS) in package_index.py.
Published 2022-12-22 · Modified
5.9EPSS 0.026