—
PYSEC-2022-260
Quick fix
PYSEC-2022-260 — mako: upgrade to the fixed version with the command below.
pip install --upgrade 'mako>=925760291d6efec64fda6e9dd1fd9cfbd5be068c'Details
Sqlalchemy mako before 1.2.2 is vulnerable to Regular expression Denial of Service when using the Lexer class to parse. This also affects babelplugin and linguaplugin.
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI/mako
Introduced in:
0Fixed in: 925760291d6efec64fda6e9dd1fd9cfbd5be068cFix
pip install --upgrade 'mako>=925760291d6efec64fda6e9dd1fd9cfbd5be068c'References
- https://github.com/sqlalchemy/mako/commit/925760291d6efec64fda6e9dd1fd9cfbd5be068c[FIX]
- https://pyup.io/vulnerabilities/CVE-2022-40023/50870/[WEB]
- https://github.com/sqlalchemy/mako/issues/366[REPORT]
- https://github.com/sqlalchemy/mako/blob/c2f392e0be52dc67d1b9770ab8cce6a9c736d547/mako/ext/extract.py#L21[WEB]
- https://github.com/advisories/GHSA-v973-fxgf-6xhp[ADVISORY]