ZeroHour

CVE-2022-40023

PoC ×2
CVSS 3.1
7.5 high
EPSS
2%p81
Published
()
Modified
Description

Sqlalchemy mako before 1.2.2 is vulnerable to Regular expression Denial of Service when using the Lexer class to parse. This also affects babelplugin and linguaplugin.

Vendors
sqlalchemydebian
Products
mako, debian linux
Weakness
CWE-1333
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.