CVE-2022-40023 Information
Sep 08, 2022
cve
Description
Sqlalchemy mako before 1.2.2 is vulnerable to Regular expression Denial of Service when using the Lexer class to parse. This also affects babelplugin and linguaplugin.
Reference
https://github.com/sqlalchemy/mako/commit/925760291d6efec64fda6e9dd1fd9cfbd5be068c https://pyup.io/vulnerabilities/CVE-2022-40023/50870/ https://github.com/sqlalchemy/mako/issues/366 https://github.com/sqlalchemy/mako/blob/c2f392e0be52dc67d1b9770ab8cce6a9c736d547/mako/ext/extract.py#L21
Share on: