Vulnerability GHSA-v973-fxgf-6xhp
High Risk
HIGH RISK
CVSS Score: 7.5
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
4 years ago
September 16, 2022 at 05:20 PM UTC
mako is vulnerable to Regular Expression Denial of Service
0.1.0 - 1.2.1
0.1.0 - 1.2.1
Summary
mako is vulnerable to Regular Expression Denial of Service
Details
Sqlalchemy mako before 1.2.2 is vulnerable to Regular expression Denial of Service when using the Lexer class to parse. This also affects babelplugin and linguaplugin.
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Medium Risk
8 hours ago
Mako: Path traversal via drive-letter URI on Windows in TemplateLookup
0.1.0 - 1.4.1 GHSA-5639-2j2p-m4mx
0.1.0 - 1.4.1 GHSA-5639-2j2p-m4mx
Unknown
2 months ago
Mako vulnerable to path traversal via backslash URI on Windows in TemplateLookup
0.1.0 - 1.3.11 PYSEC-2026-2617
0.1.0 - 1.3.11 PYSEC-2026-2617
High Risk
5 months ago
Mako vulnerable to path traversal via backslash URI on Windows in TemplateLookup
0.1.0 - 1.3.11 GHSA-2h4p-vjrc-8xpq
0.1.0 - 1.3.11 GHSA-2h4p-vjrc-8xpq
High Risk
5 months ago
No summary available
0.1.0 - 1.3.10 PYSEC-2026-88
0.1.0 - 1.3.10 PYSEC-2026-88
High Risk
5 months ago
Mako: Path traversal via double-slash URI prefix in TemplateLookup
0.1.0 - 1.3.10 GHSA-v92g-xgxw-vvmm
0.1.0 - 1.3.10 GHSA-v92g-xgxw-vvmm
Impacted packages
Timeline
Published
4 years ago
September 16, 2022 at 05:20 PM UTC
Fixed (1.2.2)
4 years ago
August 29, 2022 at 06:03 PM UTC
Last Modified
10 months ago
December 03, 2025 at 03:46 PM UTC