CVE-2022-40023EPSS p73.5%
CVE-2022-40023CVE-2022-40023
sqlalchemy / mako
Description
Sqlalchemy mako before 1.2.2 is vulnerable to Regular expression Denial of Service when using the Lexer class to parse. This also affects babelplugin and linguaplugin.
Scoring
| CVSS | 7.5 () |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
| EPSS | 1.66% probability of exploitation · percentile 73.5% · 2026-06-19T12:03:05Z |
| Last modified | 2026-06-17 |