Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-44307

Опубликовано: 12 мая 2026
Источник: redhat
CVSS3: 5.9
EPSS Низкий

Описание

Mako is a template library written in Python. Prior to 1.3.12, on Windows, a URI using backslash traversal (e.g. ....\ secret.txt) bypasses the directory traversal check in Template.init and the posixpath-based normalization in TemplateLookup.get_template(), allowing reads of files outside the configured template directory. This vulnerability is fixed in 1.3.12.

A flaw was found in Mako, a Python template library. A remote attacker could exploit a directory traversal vulnerability by crafting a Uniform Resource Identifier (URI) with backslash traversal. This bypasses security checks, allowing the attacker to read files outside the intended template directory, leading to information disclosure.

Отчет

This flaw is rated Moderate (CVSS 5.9) because exploitation requires high attack complexity (AC:H) — the path traversal is Windows-specific and depends on attacker-controlled template names being passed to Mako's TemplateLookup. Red Hat products are deployed on Linux where this vulnerability is not exploitable, as Linux does not interpret backslash as a directory separator. The Resource Optimization Service ships the affected Mako version but runs on Linux, limiting practical impact.

Меры по смягчению последствий

This vulnerability is specific to Windows systems where backslash characters are interpreted as path separators. Red Hat products running on Linux are not susceptible to this path traversal because Linux does not treat backslash as a directory separator. For any application using Mako on Windows, validate user-controlled template names to reject backslash characters before passing them to TemplateLookup.get_template(). Upgrading to Mako 1.3.12 resolves this issue.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Exploit Intelligenceexploit-intelligence-tech-preview/vulnerability-analysis-rhel9Not affected
Migration Toolkit for Applications 8mta/mta-solution-server-rhel9Not affected
Red Hat Enterprise Linux 10python-makoNot affected
Red Hat Enterprise Linux 8python-makoNot affected
Red Hat Enterprise Linux 8resource-agentsNot affected
Red Hat Enterprise Linux 9python-makoNot affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-automl-rhel9Not affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-kserve-autogluon-server-rhel9Not affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-mlflow-rhel9Not affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-pipeline-runtime-datascience-cpu-py312-rhel9Not affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-22
https://bugzilla.redhat.com/show_bug.cgi?id=2476894mako: Mako: Information disclosure via directory traversal

EPSS

Процентиль: 46%
0.00609
Низкий

5.9 Medium

CVSS3

Связанные уязвимости

ubuntu
3 месяца назад

Mako is a template library written in Python. Prior to 1.3.12, on Windows, a URI using backslash traversal (e.g. \..\..\ secret.txt) bypasses the directory traversal check in Template.__init__ and the posixpath-based normalization in TemplateLookup.get_template(), allowing reads of files outside the configured template directory. This vulnerability is fixed in 1.3.12.

nvd
3 месяца назад

Mako is a template library written in Python. Prior to 1.3.12, on Windows, a URI using backslash traversal (e.g. \..\..\ secret.txt) bypasses the directory traversal check in Template.__init__ and the posixpath-based normalization in TemplateLookup.get_template(), allowing reads of files outside the configured template directory. This vulnerability is fixed in 1.3.12.

msrc
3 месяца назад

Mako: Path traversal via backslash URI on Windows in TemplateLookup

debian
3 месяца назад

Mako is a template library written in Python. Prior to 1.3.12, on Wind ...

CVSS3: 7.5
redos
20 дней назад

Уязвимость python-mako

EPSS

Процентиль: 46%
0.00609
Низкий

5.9 Medium

CVSS3

Уязвимость CVE-2026-44307