CVE-2022-40023

HIGH

Sqlalchemy Mako < 1.2.2 - Denial of Service

Title source: rule
STIX 2.1

Description

Sqlalchemy mako before 1.2.2 is vulnerable to Regular expression Denial of Service when using the Lexer class to parse. This also affects babelplugin and linguaplugin.

Scores

CVSS v3 7.5
EPSS 0.0101
EPSS Percentile 77.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-1333
Status published
Products (3)
debian/debian_linux 10.0
pypi/mako 0 - 1.2.2PyPI
sqlalchemy/mako < 1.2.2
Published Sep 07, 2022
Tracked Since Feb 18, 2026