High severityNVD Advisory· Published Sep 7, 2022· Updated Dec 3, 2025
CVE-2022-40023
CVE-2022-40023
Description
Sqlalchemy mako before 1.2.2 is vulnerable to Regular expression Denial of Service when using the Lexer class to parse. This also affects babelplugin and linguaplugin.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
makoPyPI | < 1.2.2 | 1.2.2 |
Affected products
15- ghsa-coords14 versionspkg:pypi/makopkg:rpm/almalinux/python3-makopkg:rpm/opensuse/python-Mako&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/python-Mako&distro=openSUSE%20Leap%2015.4pkg:rpm/opensuse/python-Mako&distro=openSUSE%20Tumbleweedpkg:rpm/suse/python-Mako&distro=HPE%20Helion%20OpenStack%208pkg:rpm/suse/python-Mako&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP3pkg:rpm/suse/python-Mako&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP4pkg:rpm/suse/python-Mako&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP3pkg:rpm/suse/python-Mako&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP4pkg:rpm/suse/python-Mako&distro=SUSE%20OpenStack%20Cloud%208pkg:rpm/suse/python-Mako&distro=SUSE%20OpenStack%20Cloud%209pkg:rpm/suse/python-Mako&distro=SUSE%20OpenStack%20Cloud%20Crowbar%208pkg:rpm/suse/python-Mako&distro=SUSE%20OpenStack%20Cloud%20Crowbar%209
< 1.2.2+ 13 more
- (no CPE)range: < 1.2.2
- (no CPE)range: < 1.1.4-6.el9
- (no CPE)range: < 1.0.7-150000.3.3.1
- (no CPE)range: < 1.0.7-150000.3.3.1
- (no CPE)range: < 1.3.0-2.1
- (no CPE)range: < 1.0.7-3.3.1
- (no CPE)range: < 1.0.7-150000.3.3.1
- (no CPE)range: < 1.0.7-150000.3.3.1
- (no CPE)range: < 1.0.7-150000.3.3.1
- (no CPE)range: < 1.0.7-150000.3.3.1
- (no CPE)range: < 1.0.7-3.3.1
- (no CPE)range: < 1.0.7-4.3.1
- (no CPE)range: < 1.0.7-3.3.1
- (no CPE)range: < 1.0.7-4.3.1
Patches
Vulnerability mechanics
References
12- github.com/advisories/GHSA-v973-fxgf-6xhpghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2022-40023ghsaADVISORY
- github.com/pypa/advisory-database/tree/main/vulns/mako/PYSEC-2022-260.yamlghsaWEB
- github.com/sqlalchemy/mako/blob/c2f392e0be52dc67d1b9770ab8cce6a9c736d547/mako/ext/extract.pyghsaWEB
- github.com/sqlalchemy/mako/commit/925760291d6efec64fda6e9dd1fd9cfbd5be068cghsaWEB
- github.com/sqlalchemy/mako/issues/366ghsaWEB
- lists.debian.org/debian-lts-announce/2022/09/msg00026.htmlghsamailing-listWEB
- lists.debian.org/debian-lts-announce/2025/12/msg00004.htmlghsaWEB
- pyup.io/posts/pyup-discovers-redos-vulnerabilities-in-top-python-packagesghsaWEB
- pyup.io/vulnerabilities/CVE-2022-40023/50870ghsaWEB
- pyup.io/posts/pyup-discovers-redos-vulnerabilities-in-top-python-packages/mitre
- pyup.io/vulnerabilities/CVE-2022-40023/50870/mitre
News mentions
0No linked articles in our index yet.