CVE-2022-40023
published 2022-09-07CVE-2022-40023: Sqlalchemy mako before 1.2.2 is vulnerable to Regular expression Denial of Service when using the Lexer class to parse. This also affects babelplugin and…
PriorityP337high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
1.72%
75.2th percentile
Sqlalchemy mako before 1.2.2 is vulnerable to Regular expression Denial of Service when using the Lexer class to parse. This also affects babelplugin and linguaplugin.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | mako | < mako 1.2.2+ds1-1 (bookworm) | mako 1.2.2+ds1-1 (bookworm) |
| msrc | azl3_rust_1.75.0-14_on_azure_linux_3.0 | — | — |
| msrc | azl3_rust_1.86.0-1_on_azure_linux_3.0 | — | — |
| msrc | cbl2_python-mako_1.2.2-1_on_cbl_mariner_2.0 | — | — |
| msrc | cm1_python-mako_1.0.7-5_on_cbl_mariner_1.0 | — | — |
| sqlalchemy | mako | < 1.2.2 | 1.2.2 |
| sqlalchemy | mako | >= 0 < 1.1.3+ds1-2+deb11u1 | 1.1.3+ds1-2+deb11u1 |
| sqlalchemy | mako | >= 0 < 1.2.2+ds1-1 | 1.2.2+ds1-1 |
| sqlalchemy | mako | >= 0 < 1.2.2+ds1-1 | 1.2.2+ds1-1 |
| sqlalchemy | mako | >= 0 < 1.2.2+ds1-1 | 1.2.2+ds1-1 |
| sqlalchemy | mako | >= 0 < 1.2.2 | 1.2.2 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_debian7.5HIGH
vendor_msrc7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
mako is vulnerable to Regular Expression Denial of Service
osv·2022-09-16
CVE-2022-40023 [HIGH] mako is vulnerable to Regular Expression Denial of Service
mako is vulnerable to Regular Expression Denial of Service
Sqlalchemy mako before 1.2.2 is vulnerable to Regular expression Denial of Service when using the Lexer class to parse. This also affects babelplugin and linguaplugin.
GHSA
mako is vulnerable to Regular Expression Denial of Service
ghsa·2022-09-16
CVE-2022-40023 [HIGH] CWE-1333 mako is vulnerable to Regular Expression Denial of Service
mako is vulnerable to Regular Expression Denial of Service
Sqlalchemy mako before 1.2.2 is vulnerable to Regular expression Denial of Service when using the Lexer class to parse. This also affects babelplugin and linguaplugin.
OSV
CVE-2022-40023: Sqlalchemy mako before 1
osv·2022-09-07·CVSS 7.5
CVE-2022-40023 [HIGH] CVE-2022-40023: Sqlalchemy mako before 1
Sqlalchemy mako before 1.2.2 is vulnerable to Regular expression Denial of Service when using the Lexer class to parse. This also affects babelplugin and linguaplugin.
Ubuntu
Mako vulnerability
vendor_ubuntu·2022-11-15
CVE-2022-40023 Mako vulnerability
Title: Mako vulnerability
Summary: Mako could be made to denial of service if it received a
specially crafted regular expression.
USN-5625-1 fixed a vulnerability in Mako. This update provides the corresponding update for
Ubuntu 22.10.
Original advisory details:
It was discovered that Mako incorrectly handled certain regular expressions.
An attacker could possibly use this issue to cause a denial of service.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
Mako vulnerability
vendor_ubuntu·2022-09-21
CVE-2022-40023 Mako vulnerability
Title: Mako vulnerability
Summary: Mako could be made to denial of service if it received a
specially crafted regular expression.
It was discovered that Mako incorrectly handled certain regular expressions.
An attacker could possibly use this issue to cause a denial of service.
Instructions: In general, a standard system update will make all the necessary changes.
Microsoft
Sqlalchemy mako before 1.2.2 is vulnerable to Regular expression Denial of Service when using the Lexer class to parse. This also affects babelplugin and linguaplugin.
vendor_msrc·2022-09-13·CVSS 7.5
CVE-2022-40023 [HIGH] CWE-1333 Sqlalchemy mako before 1.2.2 is vulnerable to Regular expression Denial of Service when using the Lexer class to parse. This also affects babelplugin and linguaplugin.
Sqlalchemy mako before 1.2.2 is vulnerable to Regular expression Denial of Service when using the Lexer class to parse. This also affects babelplugin and linguaplugin.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: M
Red Hat
python-mako: REDoS in Lexer class
vendor_redhat·2022-09-07·CVSS 7.5
CVE-2022-40023 [HIGH] CWE-1333 python-mako: REDoS in Lexer class
python-mako: REDoS in Lexer class
Sqlalchemy mako before 1.2.2 is vulnerable to Regular expression Denial of Service when using the Lexer class to parse. This also affects babelplugin and linguaplugin.
A vulnerability was found in the mako package. Affected versions of this package are vulnerable to Regular expression denial of service (ReDoS) attacks, affecting system availability.
Package: python-pecan (Red Hat Ceph Storage 3) - Out of support scope
Package: python-pecan (Red Hat Ceph Storage 4) - Not affected
Package: python-pecan (Red Hat Ceph Storage 5) - Not affected
Package: python-mako (Red Hat Enterprise Linux 6) - Out of support scope
Package: python-mako (Red Hat Enterprise Linux 7) - Out of support scope
Package: resource-agents (Red Hat Enterprise Linux 7) - Out of sup
Debian
CVE-2022-40023: mako - Sqlalchemy mako before 1.2.2 is vulnerable to Regular expression Denial of Servi...
vendor_debian·2022·CVSS 7.5
CVE-2022-40023 [HIGH] CVE-2022-40023: mako - Sqlalchemy mako before 1.2.2 is vulnerable to Regular expression Denial of Servi...
Sqlalchemy mako before 1.2.2 is vulnerable to Regular expression Denial of Service when using the Lexer class to parse. This also affects babelplugin and linguaplugin.
Scope: local
bookworm: resolved (fixed in 1.2.2+ds1-1)
bullseye: resolved (fixed in 1.1.3+ds1-2+deb11u1)
forky: resolved (fixed in 1.2.2+ds1-1)
sid: resolved (fixed in 1.2.2+ds1-1)
trixie: resolved (fixed in 1.2.2+ds1-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/sqlalchemy/mako/blob/c2f392e0be52dc67d1b9770ab8cce6a9c736d547/mako/ext/extract.py#L21https://github.com/sqlalchemy/mako/commit/925760291d6efec64fda6e9dd1fd9cfbd5be068chttps://github.com/sqlalchemy/mako/issues/366https://lists.debian.org/debian-lts-announce/2022/09/msg00026.htmlhttps://pyup.io/posts/pyup-discovers-redos-vulnerabilities-in-top-python-packages/https://pyup.io/vulnerabilities/CVE-2022-40023/50870/https://github.com/sqlalchemy/mako/blob/c2f392e0be52dc67d1b9770ab8cce6a9c736d547/mako/ext/extract.py#L21https://github.com/sqlalchemy/mako/commit/925760291d6efec64fda6e9dd1fd9cfbd5be068chttps://github.com/sqlalchemy/mako/issues/366https://lists.debian.org/debian-lts-announce/2022/09/msg00026.htmlhttps://lists.debian.org/debian-lts-announce/2025/12/msg00004.htmlhttps://pyup.io/posts/pyup-discovers-redos-vulnerabilities-in-top-python-packages/https://pyup.io/vulnerabilities/CVE-2022-40023/50870/
2022-09-07
Published