{"id":"CGA-xh9x-875q-8pp6","modified":"2026-09-11T08:03:39.550669665Z","published":"2025-11-08T09:34:21Z","withdrawn":"2026-09-11T08:03:39.550669506Z","upstream":["CVE-2025-47273","GHSA-5rjg-fvgr-3xxf"],"references":[{"type":"WEB","url":"https://github.com/pypa/setuptools/blob/6ead555c5fb29bc57fe6105b1bffc163f56fd558/setuptools/package_index.py#L810C1-L825C88"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2025/05/msg00035.html"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/47xxx/CVE-2025-47273.json"},{"type":"ADVISORY","url":"https://github.com/pypa/setuptools/security/advisories/GHSA-5rjg-fvgr-3xxf"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-47273"},{"type":"REPORT","url":"https://github.com/pypa/setuptools/issues/4946"},{"type":"FIX","url":"https://github.com/pypa/setuptools/commit/250a6d17978f9f6ac3ac887091f2d32886fbbb0b"}],"affected":[{"package":{"name":"graalvm-24-graalpy","ecosystem":"Chainguard","purl":"pkg:apk/chainguard/graalvm-24-graalpy?arch=x86_64"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"ecosystem_specific":{"components":[{"component_version":"65.5.0","component_type":"python","component_location":"/usr/share/graalpy/lib/python3.11/ensurepip/_bundled/setuptools-65.5.0-py3-none-any.whl","component_purl":"pkg:pypi/setuptools@65.5.0","latest_event_status":"fix_not_planned","latest_event_timestamp":"2026-01-31T00:37:23Z","component_name":"setuptools"}]},"database_specific":{"source":"https://advisories.cgr.dev/chainguard/v3/osv/CGA-xh9x-875q-8pp6.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:P"}]}