Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:36970
HistorySep 08, 2022 - 4:31 a.m.

Regular Expression Denial Of Service (ReDoS)

2022-09-0804:31:41
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
11
mako
vulnerability
regex denial of service
lexer.py
match_tag_start function
application crash
large number
tag quotes

0.002 Low

EPSS

Percentile

60.8%

Mako is vulnerable to regular expression denial of service. The vulnerability exists due to the insecure regex pattern used for the match attribute in the match_tag_start function of lexer.py, allowing an attacker to crash the application by providing a large number of tag quotes within its quoted sections.