Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-10892.json
JSON Data
https://api.test.osv.dev/v1/vulns/AZL-10892
Upstream
Published
2022-09-07T13:15:09Z
Modified
2026-04-01T05:06:34.124872Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
CVE-2022-40023 affecting package python-mako for versions less than 1.2.2-1
Details

Sqlalchemy mako before 1.2.2 is vulnerable to Regular expression Denial of Service when using the Lexer class to parse. This also affects babelplugin and linguaplugin.

References

Affected packages

Azure Linux:2 / python-mako

Package

Name
python-mako
Purl
pkg:rpm/azure-linux/python-mako

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.2.2-1

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-10892.json"