Sqlalchemy mako before 1.2.2 is vulnerable to Regular expression Denial of Service when using the Lexer class to parse. This also affects babelplugin and linguaplugin.
{ "ubuntu_priority": "medium", "availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro", "binaries": [ { "binary_name": "python-mako", "binary_version": "1.0.3+ds1-1ubuntu1+esm1" }, { "binary_name": "python-mako-doc", "binary_version": "1.0.3+ds1-1ubuntu1+esm1" }, { "binary_name": "python3-mako", "binary_version": "1.0.3+ds1-1ubuntu1+esm1" } ] }
{ "ubuntu_priority": "medium", "availability": "No subscription required", "binaries": [ { "binary_name": "python-mako", "binary_version": "1.0.7+ds1-1ubuntu0.2" }, { "binary_name": "python-mako-doc", "binary_version": "1.0.7+ds1-1ubuntu0.2" }, { "binary_name": "python3-mako", "binary_version": "1.0.7+ds1-1ubuntu0.2" } ] }
{ "ubuntu_priority": "medium", "availability": "No subscription required", "binaries": [ { "binary_name": "python-mako", "binary_version": "1.1.0+ds1-1ubuntu2.1" }, { "binary_name": "python-mako-doc", "binary_version": "1.1.0+ds1-1ubuntu2.1" }, { "binary_name": "python3-mako", "binary_version": "1.1.0+ds1-1ubuntu2.1" } ] }