Description
Sqlalchemy mako before 1.2.2 is vulnerable to Regular expression Denial of Service when using the Lexer class to parse. This also affects babelplugin and linguaplugin.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-3116-1 | mako security update |
Debian DLA |
DLA-4393-1 | mako security update |
EUVD |
EUVD-2022-0149 | Sqlalchemy mako before 1.2.2 is vulnerable to Regular expression Denial of Service when using the Lexer class to parse. This also affects babelplugin and linguaplugin. |
Github GHSA |
GHSA-v973-fxgf-6xhp | mako is vulnerable to Regular Expression Denial of Service |
Ubuntu USN |
USN-5625-1 | Mako vulnerability |
Ubuntu USN |
USN-5625-2 | Mako vulnerability |
References
History
Wed, 03 Dec 2025 07:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-12-03T06:05:04.544Z
Reserved: 2022-09-06T00:00:00.000Z
Link: CVE-2022-40023
No data.
Status : Modified
Published: 2022-09-07T13:15:09.953
Modified: 2025-12-03T07:16:01.227
Link: CVE-2022-40023
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
EUVD
Github GHSA
Ubuntu USN