Python/setuptools/61.2.0


Easily download, build, install, upgrade, and uninstall Python packages

https://pypi.org/project/setuptools
MIT

3 Security Vulnerabilities

setuptools has a path traversal vulnerability in PackageIndex.download that leads to Arbitrary File Write

Published date: 2025-05-19T16:52:43Z
CVE: CVE-2025-47273
Links:

Summary

A path traversal vulnerability in PackageIndex was fixed in setuptools version 78.1.1

Details

    def _download_url(self, url, tmpdir):
        # Determine download filename
        #
        name, _fragment = egg_info_for_url(url)
        if name:
            while '..' in name:
                name = name.replace('..', '.').replace('\\', '_')
        else:
            name = "__downloaded__"  # default if URL has no path contents

        if name.endswith('.[egg.zip](http://egg.zip/)'):
            name = name[:-4]  # strip the extra .zip before download

 -->       filename = os.path.join(tmpdir, name)

Here: https://github.com/pypa/setuptools/blob/6ead555c5fb29bc57fe6105b1bffc163f56fd558/setuptools/package_index.py#L810C1-L825C88

os.path.join() discards the first argument tmpdir if the second begins with a slash or drive letter. name is derived from a URL without sufficient sanitization. While there is some attempt to sanitize by replacing instances of '..' with '.', it is insufficient.

Risk Assessment

As easyinstall and packageindex are deprecated, the exploitation surface is reduced. However, it seems this could be exploited in a similar fashion like https://github.com/advisories/GHSA-r9hx-vwmv-q579, and as described by POC 4 in https://github.com/advisories/GHSA-cx63-2mw6-8hw5 report: via malicious URLs present on the pages of a package index.

Impact

An attacker would be allowed to write files to arbitrary locations on the filesystem with the permissions of the process running the Python code, which could escalate to RCE depending on the context.

References

https://huntr.com/bounties/d6362117-ad57-4e83-951f-b8141c6e7ca5 https://github.com/pypa/setuptools/issues/4946

Affected versions: ["0.6c10", "0.6c3", "0.6c8", "0.7.4", "0.7.6", "0.9.3", "1.1", "1.3.2", "10.1", "0.6c7", "0.8", "0.9.4", "1.1.5", "1.4.1", "12.0.4", "0.6b4", "0.6c9", "0.7.5", "0.7.8", "0.9.1", "11.0", "12.0.1", "0.6c11", "0.6c2", "0.6c6", "0.7.2", "1.3", "1.3.1", "12.0", "12.0.2", "0.6b1", "0.7.7", "0.9.8", "1.1.1", "1.1.3", "10.0.1", "10.2.1", "12.0.5", "13.0", "17.0", "17.1", "18.6", "21.2.0", "21.2.2", "22.0.1", "23.0.0", "23.2.0", "23.2.1", "25.2.0", "26.0.0", "27.0.0", "27.1.2", "28.6.1", "28.7.1", "28.8.0", "29.0.0", "3.0", "3.2", "30.0.0", "30.4.0", "34.3.2", "36.2.2", "36.2.6", "39.1.0", "4.0.1", "40.4.1", "40.4.2", "41.2.0", "44.1.1", "47.0.0", "5.1", "50.0.3", "50.3.2", "51.0.0", "14.0", "14.3", "15.0", "15.1", "18.0", "19.1.1", "19.4.1", "19.6.2", "2.1", "2.1.1", "20.10.1", "20.7.0", "24.1.1", "24.2.1", "24.3.1", "26.1.1", "28.7.0", "3.0.2", "3.4.1", "3.4.2", "32.3.0", "34.0.3", "34.2.0", "35.0.0", "36.2.0", "36.2.1", "37.0.0", "38.2.3", "38.2.5", "40.1.1", "40.6.2", "40.8.0", "40.9.0", "42.0.1", "45.1.0", "45.3.0", "46.1.0", "47.1.0", "47.3.0", "49.3.2", "5.0.1", "5.3", "5.4", "5.6", "50.3.0", "51.3.2", "8.0.1", "9.0.1", "1.0", "11.2", "11.3.1", "14.3.1", "18.3.1", "18.7", "18.8.1", "19.7", "20.1", "20.3.1", "20.4", "20.6.6", "20.6.8", "24.2.0", "25.4.0", "28.0.0", "29.0.1", "3.4.3", "3.8", "30.2.0", "32.1.1", "33.1.0", "36.0.1", "36.2.4", "36.2.5", "36.6.0", "38.2.1", "38.4.0", "40.1.0", "40.6.0", "40.6.3", "40.7.1", "40.7.3", "42.0.0", "46.4.0", "47.1.1", "5.2", "5.4.1", "51.3.1", "54.1.1", "8.1", "13.0.2", "18.0.1", "18.3", "18.4", "18.6.1", "19.1", "19.2", "2.0", "2.0.1", "2.0.2", "20.2.2", "20.9.0", "22.0.4", "27.3.0", "28.4.0", "3.3", "3.7", "30.1.0", "32.0.0", "32.1.3", "32.2.0", "34.0.1", "34.4.0", "36.7.2", "38.2.4", "38.6.1", "39.0.1", "39.2.0", "40.4.0", "40.6.1", "41.1.0", "43.0.0", "46.1.1", "46.3.0", "47.2.0", "49.2.1", "49.4.0", "5.4.2", "50.0.2", "51.1.1", "54.1.0", "54.1.3", "0.6b2", "0.6b3", "0.9.2", "0.9.7", "1.1.2", "1.1.6", "1.2", "1.4", "1.4.2", "10.0", "11.1", "11.3", "12.1", "12.2", "13.0.1", "14.1", "16.0", "18.1", "19.0", "19.6", "22.0.2", "22.0.5", "24.0.0", "24.1.0", "24.3.0", "25.0.0", "25.1.4", "25.1.6", "26.1.0", "27.3.1", "28.1.0", "28.8.1", "3.1", "3.5.2", "3.8.1", "31.0.0", "32.1.0", "32.1.2", "32.3.1", "34.3.3", "34.4.1", "35.0.1", "36.2.7", "36.8.0", "38.7.0", "40.2.0", "40.5.0", "41.0.1", "41.5.0", "41.6.0", "46.1.2", "46.2.0", "47.3.1", "49.0.0", "49.1.1", "49.1.2", "49.2.0", "49.3.1", "0.6c1", "0.6c4", "0.6c5", "0.7.3", "0.9", "0.9.5", "0.9.6", "1.1.4", "1.1.7", "10.2", "12.0.3", "12.3", "12.4", "15.2", "18.2", "18.7.1", "19.5", "20.3", "21.1.0", "22.0.0", "24.0.1", "24.0.3", "25.3.0", "28.2.0", "28.5.0", "3.7.1", "33.1.1", "34.1.0", "34.3.1", "36.2.3", "36.3.0", "36.5.0", "38.3.0", "38.4.1", "38.5.0", "39.0.0", "4.0", "40.3.0", "40.4.3", "45.0.0", "46.1.3", "48.0.0", "49.0.1", "49.1.0", "49.3.0", "5.5", "5.7", "5.8", "50.0.0", "51.1.0", "51.1.2", "51.3.3", "56.0.0", "8.0.3", "9.1", "18.3.2", "18.5", "18.8", "19.4", "19.6.1", "2.2", "20.0", "20.6.7", "20.8.0", "23.1.0", "25.0.2", "25.1.5", "28.3.0", "28.6.0", "3.0.1", "3.4", "3.5", "3.5.1", "3.6", "30.2.1", "34.0.0", "34.1.1", "34.3.0", "36.1.1", "36.6.1", "38.2.0", "38.5.1", "40.7.0", "41.0.0", "41.3.0", "41.4.0", "42.0.2", "46.0.0", "49.6.0", "5.5.1", "50.1.0", "50.2.0", "54.0.0", "6.1", "7.0", "8.0.2", "8.0.4", "5.0.2", "50.0.1", "50.3.1", "51.1.0.post20201221", "51.2.0", "51.3.0", "53.0.0", "54.2.0", "6.0.1", "8.0", "8.2", "9.0", "14.1.1", "14.2", "17.1.1", "19.3", "2.1.2", "20.1.1", "20.8.1", "21.0.0", "21.2.1", "24.0.2", "25.0.1", "25.1.0", "25.1.1", "25.1.2", "25.1.3", "27.1.0", "27.2.0", "3.4.4", "30.3.0", "31.0.1", "34.0.2", "35.0.2", "36.1.0", "36.4.0", "36.7.0", "36.7.1", "38.0.0", "38.1.0", "38.5.2", "38.6.0", "40.0.0", "40.7.2", "41.5.1", "44.0.0", "44.1.0", "45.2.0", "46.3.1", "47.3.2", "49.1.3", "49.5.0", "5.0", "52.0.0", "53.1.0", "54.1.2", "6.0.2", "8.2.1", "8.3", "56.1.0", "56.2.0", "57.0.0", "57.1.0", "57.2.0", "57.3.0", "57.4.0", "57.5.0", "58.0.2", "58.0.1", "58.0.0", "58.0.3", "58.0.4", "58.1.0", "58.2.0", "58.3.0", "58.4.0", "58.5.0", "58.5.1", "58.5.2", "58.5.3", "59.1.0", "59.0.1", "59.1.1", "59.2.0", "59.3.0", "59.4.0", "59.5.0", "59.6.0", "59.7.0", "60.0.0", "59.8.0", "60.0.3", "60.0.1", "60.0.2", "60.0.4", "60.0.5", "60.1.0", "60.1.1", "60.2.0", "60.3.1", "60.3.0", "60.4.0", "60.5.0", "60.6.0", "60.7.0", "60.7.1", "60.8.0", "60.8.1", "60.8.2", "60.9.0", "60.9.1", "60.9.2", "60.9.3", "60.10.0", "61.0.0", "61.1.0", "61.2.0", "61.1.1", "61.3.0", "61.3.1", "62.0.0", "62.1.0", "62.2.0", "62.3.0", "62.3.1", "62.3.2", "62.3.3", "62.3.4", "62.4.0", "62.5.0", "62.6.0", "63.0.0b1", "63.0.0", "63.1.0", "63.2.0", "63.3.0", "63.4.0", "63.4.1", "63.4.2", "63.4.3", "64.0.0", "64.0.1", "64.0.2", "64.0.3", "65.0.0", "65.0.1", "65.0.2", "65.1.0", "65.1.1", "65.2.0", "65.3.0", "65.4.0", "65.4.1", "65.5.0", "65.5.1", "65.6.0", "65.6.1", "65.6.2", "65.6.3", "65.7.0", "66.0.0", "66.1.1", "66.1.0", "67.0.0", "67.1.0", "67.2.0", "67.3.1", "67.3.2", "67.3.3", "67.4.0", "67.5.0", "67.5.1", "67.6.0", "67.6.1", "67.7.0", "67.7.1", "67.7.2", "67.8.0", "68.0.0", "68.1.0", "68.1.2", "68.2.0", "68.2.1", "68.2.2", "69.0.0", "69.0.1", "69.0.2", "69.0.3", "69.1.0", "69.1.1", "69.2.0", "69.4.0", "69.3.0", "69.4.2", "69.4.1", "69.5.1", "69.3.1", "69.5.0", "70.0.0", "70.1.0", "70.1.1", "70.2.0", "70.3.0", "71.0.1", "71.0.0", "71.0.3", "71.0.2", "71.0.4", "71.1.0", "72.0.0", "72.1.0", "72.2.0", "73.0.0", "73.0.1", "74.0.0", "74.1.0", "74.1.1", "74.1.2", "75.0.0", "74.1.3", "75.1.0", "75.2.0", "75.3.0", "75.4.0", "75.5.0", "75.6.0", "75.7.0", "75.8.0", "75.8.1", "75.8.2", "75.9.1", "75.9.0", "76.0.0", "75.3.1", "75.3.2", "76.1.0", "77.0.1", "77.0.3", "78.0.1", "78.0.2", "78.1.0"]
Secure versions: [78.1.1, 79.0.0, 79.0.1, 80.0.0, 80.0.1, 80.1.0, 80.2.0, 80.3.0, 80.3.1, 80.4.0, 80.6.0, 80.7.0, 80.7.1, 80.8.0, 80.9.0]
Recommendation: Update to version 80.9.0.

setuptools vulnerable to Command Injection via package URL

Published date: 2024-07-15T03:30:57Z
CVE: CVE-2024-6345
Links:

A vulnerability in the package_index module of pypa/setuptools versions up to 69.1.1 allows for remote code execution via its download functions. These functions, which are used to download packages from URLs provided by users or retrieved from package index servers, are susceptible to code injection. If these functions are exposed to user-controlled inputs, such as package URLs, they can execute arbitrary commands on the system. The issue is fixed in version 70.0.

Affected versions: ["0.6c10", "0.6c3", "0.6c8", "0.7.4", "0.7.6", "0.9.3", "1.1", "1.3.2", "10.1", "0.6c7", "0.8", "0.9.4", "1.1.5", "1.4.1", "12.0.4", "0.6b4", "0.6c9", "0.7.5", "0.7.8", "0.9.1", "11.0", "12.0.1", "0.6c11", "0.6c2", "0.6c6", "0.7.2", "1.3", "1.3.1", "12.0", "12.0.2", "0.6b1", "0.7.7", "0.9.8", "1.1.1", "1.1.3", "10.0.1", "10.2.1", "12.0.5", "13.0", "17.0", "17.1", "18.6", "21.2.0", "21.2.2", "22.0.1", "23.0.0", "23.2.0", "23.2.1", "25.2.0", "26.0.0", "27.0.0", "27.1.2", "28.6.1", "28.7.1", "28.8.0", "29.0.0", "3.0", "3.2", "30.0.0", "30.4.0", "34.3.2", "36.2.2", "36.2.6", "39.1.0", "4.0.1", "40.4.1", "40.4.2", "41.2.0", "44.1.1", "47.0.0", "5.1", "50.0.3", "50.3.2", "51.0.0", "14.0", "14.3", "15.0", "15.1", "18.0", "19.1.1", "19.4.1", "19.6.2", "2.1", "2.1.1", "20.10.1", "20.7.0", "24.1.1", "24.2.1", "24.3.1", "26.1.1", "28.7.0", "3.0.2", "3.4.1", "3.4.2", "32.3.0", "34.0.3", "34.2.0", "35.0.0", "36.2.0", "36.2.1", "37.0.0", "38.2.3", "38.2.5", "40.1.1", "40.6.2", "40.8.0", "40.9.0", "42.0.1", "45.1.0", "45.3.0", "46.1.0", "47.1.0", "47.3.0", "49.3.2", "5.0.1", "5.3", "5.4", "5.6", "50.3.0", "51.3.2", "8.0.1", "9.0.1", "1.0", "11.2", "11.3.1", "14.3.1", "18.3.1", "18.7", "18.8.1", "19.7", "20.1", "20.3.1", "20.4", "20.6.6", "20.6.8", "24.2.0", "25.4.0", "28.0.0", "29.0.1", "3.4.3", "3.8", "30.2.0", "32.1.1", "33.1.0", "36.0.1", "36.2.4", "36.2.5", "36.6.0", "38.2.1", "38.4.0", "40.1.0", "40.6.0", "40.6.3", "40.7.1", "40.7.3", "42.0.0", "46.4.0", "47.1.1", "5.2", "5.4.1", "51.3.1", "54.1.1", "8.1", "13.0.2", "18.0.1", "18.3", "18.4", "18.6.1", "19.1", "19.2", "2.0", "2.0.1", "2.0.2", "20.2.2", "20.9.0", "22.0.4", "27.3.0", "28.4.0", "3.3", "3.7", "30.1.0", "32.0.0", "32.1.3", "32.2.0", "34.0.1", "34.4.0", "36.7.2", "38.2.4", "38.6.1", "39.0.1", "39.2.0", "40.4.0", "40.6.1", "41.1.0", "43.0.0", "46.1.1", "46.3.0", "47.2.0", "49.2.1", "49.4.0", "5.4.2", "50.0.2", "51.1.1", "54.1.0", "54.1.3", "0.6b2", "0.6b3", "0.9.2", "0.9.7", "1.1.2", "1.1.6", "1.2", "1.4", "1.4.2", "10.0", "11.1", "11.3", "12.1", "12.2", "13.0.1", "14.1", "16.0", "18.1", "19.0", "19.6", "22.0.2", "22.0.5", "24.0.0", "24.1.0", "24.3.0", "25.0.0", "25.1.4", "25.1.6", "26.1.0", "27.3.1", "28.1.0", "28.8.1", "3.1", "3.5.2", "3.8.1", "31.0.0", "32.1.0", "32.1.2", "32.3.1", "34.3.3", "34.4.1", "35.0.1", "36.2.7", "36.8.0", "38.7.0", "40.2.0", "40.5.0", "41.0.1", "41.5.0", "41.6.0", "46.1.2", "46.2.0", "47.3.1", "49.0.0", "49.1.1", "49.1.2", "49.2.0", "49.3.1", "0.6c1", "0.6c4", "0.6c5", "0.7.3", "0.9", "0.9.5", "0.9.6", "1.1.4", "1.1.7", "10.2", "12.0.3", "12.3", "12.4", "15.2", "18.2", "18.7.1", "19.5", "20.3", "21.1.0", "22.0.0", "24.0.1", "24.0.3", "25.3.0", "28.2.0", "28.5.0", "3.7.1", "33.1.1", "34.1.0", "34.3.1", "36.2.3", "36.3.0", "36.5.0", "38.3.0", "38.4.1", "38.5.0", "39.0.0", "4.0", "40.3.0", "40.4.3", "45.0.0", "46.1.3", "48.0.0", "49.0.1", "49.1.0", "49.3.0", "5.5", "5.7", "5.8", "50.0.0", "51.1.0", "51.1.2", "51.3.3", "56.0.0", "8.0.3", "9.1", "18.3.2", "18.5", "18.8", "19.4", "19.6.1", "2.2", "20.0", "20.6.7", "20.8.0", "23.1.0", "25.0.2", "25.1.5", "28.3.0", "28.6.0", "3.0.1", "3.4", "3.5", "3.5.1", "3.6", "30.2.1", "34.0.0", "34.1.1", "34.3.0", "36.1.1", "36.6.1", "38.2.0", "38.5.1", "40.7.0", "41.0.0", "41.3.0", "41.4.0", "42.0.2", "46.0.0", "49.6.0", "5.5.1", "50.1.0", "50.2.0", "54.0.0", "6.1", "7.0", "8.0.2", "8.0.4", "5.0.2", "50.0.1", "50.3.1", "51.1.0.post20201221", "51.2.0", "51.3.0", "53.0.0", "54.2.0", "6.0.1", "8.0", "8.2", "9.0", "14.1.1", "14.2", "17.1.1", "19.3", "2.1.2", "20.1.1", "20.8.1", "21.0.0", "21.2.1", "24.0.2", "25.0.1", "25.1.0", "25.1.1", "25.1.2", "25.1.3", "27.1.0", "27.2.0", "3.4.4", "30.3.0", "31.0.1", "34.0.2", "35.0.2", "36.1.0", "36.4.0", "36.7.0", "36.7.1", "38.0.0", "38.1.0", "38.5.2", "38.6.0", "40.0.0", "40.7.2", "41.5.1", "44.0.0", "44.1.0", "45.2.0", "46.3.1", "47.3.2", "49.1.3", "49.5.0", "5.0", "52.0.0", "53.1.0", "54.1.2", "6.0.2", "8.2.1", "8.3", "56.1.0", "56.2.0", "57.0.0", "57.1.0", "57.2.0", "57.3.0", "57.4.0", "57.5.0", "58.0.2", "58.0.1", "58.0.0", "58.0.3", "58.0.4", "58.1.0", "58.2.0", "58.3.0", "58.4.0", "58.5.0", "58.5.1", "58.5.2", "58.5.3", "59.1.0", "59.0.1", "59.1.1", "59.2.0", "59.3.0", "59.4.0", "59.5.0", "59.6.0", "59.7.0", "60.0.0", "59.8.0", "60.0.3", "60.0.1", "60.0.2", "60.0.4", "60.0.5", "60.1.0", "60.1.1", "60.2.0", "60.3.1", "60.3.0", "60.4.0", "60.5.0", "60.6.0", "60.7.0", "60.7.1", "60.8.0", "60.8.1", "60.8.2", "60.9.0", "60.9.1", "60.9.2", "60.9.3", "60.10.0", "61.0.0", "61.1.0", "61.2.0", "61.1.1", "61.3.0", "61.3.1", "62.0.0", "62.1.0", "62.2.0", "62.3.0", "62.3.1", "62.3.2", "62.3.3", "62.3.4", "62.4.0", "62.5.0", "62.6.0", "63.0.0b1", "63.0.0", "63.1.0", "63.2.0", "63.3.0", "63.4.0", "63.4.1", "63.4.2", "63.4.3", "64.0.0", "64.0.1", "64.0.2", "64.0.3", "65.0.0", "65.0.1", "65.0.2", "65.1.0", "65.1.1", "65.2.0", "65.3.0", "65.4.0", "65.4.1", "65.5.0", "65.5.1", "65.6.0", "65.6.1", "65.6.2", "65.6.3", "65.7.0", "66.0.0", "66.1.1", "66.1.0", "67.0.0", "67.1.0", "67.2.0", "67.3.1", "67.3.2", "67.3.3", "67.4.0", "67.5.0", "67.5.1", "67.6.0", "67.6.1", "67.7.0", "67.7.1", "67.7.2", "67.8.0", "68.0.0", "68.1.0", "68.1.2", "68.2.0", "68.2.1", "68.2.2", "69.0.0", "69.0.1", "69.0.2", "69.0.3", "69.1.0", "69.1.1", "69.2.0", "69.4.0", "69.3.0", "69.4.2", "69.4.1", "69.5.1", "69.3.1", "69.5.0"]
Secure versions: [78.1.1, 79.0.0, 79.0.1, 80.0.0, 80.0.1, 80.1.0, 80.2.0, 80.3.0, 80.3.1, 80.4.0, 80.6.0, 80.7.0, 80.7.1, 80.8.0, 80.9.0]
Recommendation: Update to version 80.9.0.

pypa/setuptools vulnerable to Regular Expression Denial of Service (ReDoS)

Published date: 2022-12-23T00:30:23Z
CVE: CVE-2022-40897
Links:

Python Packaging Authority (PyPA)'s setuptools is a library designed to facilitate packaging Python projects. Setuptools version 65.5.0 and earlier could allow remote attackers to cause a denial of service by fetching malicious HTML from a PyPI package or custom PackageIndex page due to a vulnerable Regular Expression in package_index. This has been patched in version 65.5.1.

Affected versions: ["0.6c10", "0.6c3", "0.6c8", "0.7.4", "0.7.6", "0.9.3", "1.1", "1.3.2", "10.1", "0.6c7", "0.8", "0.9.4", "1.1.5", "1.4.1", "12.0.4", "0.6b4", "0.6c9", "0.7.5", "0.7.8", "0.9.1", "11.0", "12.0.1", "0.6c11", "0.6c2", "0.6c6", "0.7.2", "1.3", "1.3.1", "12.0", "12.0.2", "0.6b1", "0.7.7", "0.9.8", "1.1.1", "1.1.3", "10.0.1", "10.2.1", "12.0.5", "13.0", "17.0", "17.1", "18.6", "21.2.0", "21.2.2", "22.0.1", "23.0.0", "23.2.0", "23.2.1", "25.2.0", "26.0.0", "27.0.0", "27.1.2", "28.6.1", "28.7.1", "28.8.0", "29.0.0", "3.0", "3.2", "30.0.0", "30.4.0", "34.3.2", "36.2.2", "36.2.6", "39.1.0", "4.0.1", "40.4.1", "40.4.2", "41.2.0", "44.1.1", "47.0.0", "5.1", "50.0.3", "50.3.2", "51.0.0", "14.0", "14.3", "15.0", "15.1", "18.0", "19.1.1", "19.4.1", "19.6.2", "2.1", "2.1.1", "20.10.1", "20.7.0", "24.1.1", "24.2.1", "24.3.1", "26.1.1", "28.7.0", "3.0.2", "3.4.1", "3.4.2", "32.3.0", "34.0.3", "34.2.0", "35.0.0", "36.2.0", "36.2.1", "37.0.0", "38.2.3", "38.2.5", "40.1.1", "40.6.2", "40.8.0", "40.9.0", "42.0.1", "45.1.0", "45.3.0", "46.1.0", "47.1.0", "47.3.0", "49.3.2", "5.0.1", "5.3", "5.4", "5.6", "50.3.0", "51.3.2", "8.0.1", "9.0.1", "1.0", "11.2", "11.3.1", "14.3.1", "18.3.1", "18.7", "18.8.1", "19.7", "20.1", "20.3.1", "20.4", "20.6.6", "20.6.8", "24.2.0", "25.4.0", "28.0.0", "29.0.1", "3.4.3", "3.8", "30.2.0", "32.1.1", "33.1.0", "36.0.1", "36.2.4", "36.2.5", "36.6.0", "38.2.1", "38.4.0", "40.1.0", "40.6.0", "40.6.3", "40.7.1", "40.7.3", "42.0.0", "46.4.0", "47.1.1", "5.2", "5.4.1", "51.3.1", "54.1.1", "8.1", "13.0.2", "18.0.1", "18.3", "18.4", "18.6.1", "19.1", "19.2", "2.0", "2.0.1", "2.0.2", "20.2.2", "20.9.0", "22.0.4", "27.3.0", "28.4.0", "3.3", "3.7", "30.1.0", "32.0.0", "32.1.3", "32.2.0", "34.0.1", "34.4.0", "36.7.2", "38.2.4", "38.6.1", "39.0.1", "39.2.0", "40.4.0", "40.6.1", "41.1.0", "43.0.0", "46.1.1", "46.3.0", "47.2.0", "49.2.1", "49.4.0", "5.4.2", "50.0.2", "51.1.1", "54.1.0", "54.1.3", "0.6b2", "0.6b3", "0.9.2", "0.9.7", "1.1.2", "1.1.6", "1.2", "1.4", "1.4.2", "10.0", "11.1", "11.3", "12.1", "12.2", "13.0.1", "14.1", "16.0", "18.1", "19.0", "19.6", "22.0.2", "22.0.5", "24.0.0", "24.1.0", "24.3.0", "25.0.0", "25.1.4", "25.1.6", "26.1.0", "27.3.1", "28.1.0", "28.8.1", "3.1", "3.5.2", "3.8.1", "31.0.0", "32.1.0", "32.1.2", "32.3.1", "34.3.3", "34.4.1", "35.0.1", "36.2.7", "36.8.0", "38.7.0", "40.2.0", "40.5.0", "41.0.1", "41.5.0", "41.6.0", "46.1.2", "46.2.0", "47.3.1", "49.0.0", "49.1.1", "49.1.2", "49.2.0", "49.3.1", "0.6c1", "0.6c4", "0.6c5", "0.7.3", "0.9", "0.9.5", "0.9.6", "1.1.4", "1.1.7", "10.2", "12.0.3", "12.3", "12.4", "15.2", "18.2", "18.7.1", "19.5", "20.3", "21.1.0", "22.0.0", "24.0.1", "24.0.3", "25.3.0", "28.2.0", "28.5.0", "3.7.1", "33.1.1", "34.1.0", "34.3.1", "36.2.3", "36.3.0", "36.5.0", "38.3.0", "38.4.1", "38.5.0", "39.0.0", "4.0", "40.3.0", "40.4.3", "45.0.0", "46.1.3", "48.0.0", "49.0.1", "49.1.0", "49.3.0", "5.5", "5.7", "5.8", "50.0.0", "51.1.0", "51.1.2", "51.3.3", "56.0.0", "8.0.3", "9.1", "18.3.2", "18.5", "18.8", "19.4", "19.6.1", "2.2", "20.0", "20.6.7", "20.8.0", "23.1.0", "25.0.2", "25.1.5", "28.3.0", "28.6.0", "3.0.1", "3.4", "3.5", "3.5.1", "3.6", "30.2.1", "34.0.0", "34.1.1", "34.3.0", "36.1.1", "36.6.1", "38.2.0", "38.5.1", "40.7.0", "41.0.0", "41.3.0", "41.4.0", "42.0.2", "46.0.0", "49.6.0", "5.5.1", "50.1.0", "50.2.0", "54.0.0", "6.1", "7.0", "8.0.2", "8.0.4", "5.0.2", "50.0.1", "50.3.1", "51.1.0.post20201221", "51.2.0", "51.3.0", "53.0.0", "54.2.0", "6.0.1", "8.0", "8.2", "9.0", "14.1.1", "14.2", "17.1.1", "19.3", "2.1.2", "20.1.1", "20.8.1", "21.0.0", "21.2.1", "24.0.2", "25.0.1", "25.1.0", "25.1.1", "25.1.2", "25.1.3", "27.1.0", "27.2.0", "3.4.4", "30.3.0", "31.0.1", "34.0.2", "35.0.2", "36.1.0", "36.4.0", "36.7.0", "36.7.1", "38.0.0", "38.1.0", "38.5.2", "38.6.0", "40.0.0", "40.7.2", "41.5.1", "44.0.0", "44.1.0", "45.2.0", "46.3.1", "47.3.2", "49.1.3", "49.5.0", "5.0", "52.0.0", "53.1.0", "54.1.2", "6.0.2", "8.2.1", "8.3", "56.1.0", "56.2.0", "57.0.0", "57.1.0", "57.2.0", "57.3.0", "57.4.0", "57.5.0", "58.0.2", "58.0.1", "58.0.0", "58.0.3", "58.0.4", "58.1.0", "58.2.0", "58.3.0", "58.4.0", "58.5.0", "58.5.1", "58.5.2", "58.5.3", "59.1.0", "59.0.1", "59.1.1", "59.2.0", "59.3.0", "59.4.0", "59.5.0", "59.6.0", "59.7.0", "60.0.0", "59.8.0", "60.0.3", "60.0.1", "60.0.2", "60.0.4", "60.0.5", "60.1.0", "60.1.1", "60.2.0", "60.3.1", "60.3.0", "60.4.0", "60.5.0", "60.6.0", "60.7.0", "60.7.1", "60.8.0", "60.8.1", "60.8.2", "60.9.0", "60.9.1", "60.9.2", "60.9.3", "60.10.0", "61.0.0", "61.1.0", "61.2.0", "61.1.1", "61.3.0", "61.3.1", "62.0.0", "62.1.0", "62.2.0", "62.3.0", "62.3.1", "62.3.2", "62.3.3", "62.3.4", "62.4.0", "62.5.0", "62.6.0", "63.0.0b1", "63.0.0", "63.1.0", "63.2.0", "63.3.0", "63.4.0", "63.4.1", "63.4.2", "63.4.3", "64.0.0", "64.0.1", "64.0.2", "64.0.3", "65.0.0", "65.0.1", "65.0.2", "65.1.0", "65.1.1", "65.2.0", "65.3.0", "65.4.0", "65.4.1", "65.5.0"]
Secure versions: [78.1.1, 79.0.0, 79.0.1, 80.0.0, 80.0.1, 80.1.0, 80.2.0, 80.3.0, 80.3.1, 80.4.0, 80.6.0, 80.7.0, 80.7.1, 80.8.0, 80.9.0]
Recommendation: Update to version 80.9.0.

616 Other Versions

Version License Security Released
0.7.2 PSF-2.0 OR ZPL-2.1 3 2013-06-09 - 16:10 over 12 years
0.6c10 PSF-2.0 OR ZPL-2.1 4 2009-10-19 - 21:49 about 16 years
0.6c3 PSF-2.0 OR ZPL-2.1 4 2006-09-20 - 21:30 about 19 years
0.6c8 PSF-2.0 OR ZPL-2.1 4 2008-02-15 - 18:13 almost 18 years
0.6c7 PSF-2.0 OR ZPL-2.1 4 2007-09-04 - 16:48 over 18 years
0.6b4 PSF-2.0 OR ZPL-2.1 4 2006-07-11 - 18:51 over 19 years
0.6c9 PSF-2.0 OR ZPL-2.1 4 2008-09-24 - 17:23 about 17 years
0.6c11 PSF-2.0 OR ZPL-2.1 4 2009-10-20 - 16:07 about 16 years
0.6c2 PSF-2.0 OR ZPL-2.1 4 2006-09-06 - 21:26 over 19 years
0.6c6 PSF-2.0 OR ZPL-2.1 4 2007-05-31 - 17:32 over 18 years
0.6b1 PSF-2.0 OR ZPL-2.1 4 2006-05-12 - 22:42 over 19 years
0.6b2 PSF-2.0 OR ZPL-2.1 4 2006-06-01 - 15:45 over 19 years
0.6b3 PSF-2.0 OR ZPL-2.1 4 2006-06-09 - 18:48 over 19 years
0.6c1 PSF-2.0 OR ZPL-2.1 4 2006-07-20 - 21:03 over 19 years
0.6c4 PSF-2.0 OR ZPL-2.1 4 2007-01-09 - 18:22 almost 19 years
0.6c5 PSF-2.0 OR ZPL-2.1 4 2007-01-09 - 19:39 almost 19 years