CVE-2022-40023

HIGH

Mako < 1.2.2 - Regular Expression Denial of Service via Lexer Class

Title source: llm
STIX 2.1

Description

Sqlalchemy mako before 1.2.2 is vulnerable to Regular expression Denial of Service when using the Lexer class to parse. This also affects babelplugin and linguaplugin.

Scores

CVSS v3 7.5
EPSS 0.0162
EPSS Percentile 72.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-1333
Status published
Products (3)
debian/debian_linux 10.0
pypi/mako 0 - 1.2.2PyPI
sqlalchemy/mako < 1.2.2
Published Sep 07, 2022
Tracked Since Feb 18, 2026