Asymmetric denial of service - ReDoS In mako
Description
mako is vulnerable to Regular Expression Denial of Service Sqlalchemy mako before 1.2.2 is vulnerable to Regular expression Denial of Service when using the Lexer class to parse. This also affects babelplugin and linguaplugin.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
pypi | 1.2.2 | ||
alpine v3.16 | 1.2.2-r0 | ||
alpine v3.18 | 1.2.2-r0 | ||
alpine v3.19 | 1.2.2-r0 | ||
alpine v3.20 | 1.2.2-r0 | ||
debian 13 | 1.2.2+ds1-1 | ||
alpine v3.17 | 1.2.2-r0 | ||
alpine v3.21 | 1.2.2-r0 | ||
alpine v3.22 | 1.2.2-r0 | ||
debian 12 | 1.2.2+ds1-1 |
1-10 of 19
10
Aliases
1. 2. 3. 4. 5. 6. 7. 8. 9. 10. 11.
References
1. 2. 3. 4. 5. 6. 7.