CVE-2026-41205: Mako: Path traversal via double-slash URI prefix in TemplateLookup

Overview

Severity
N/A
Exploit Status
Not Exploited
Patch Tuesday
2026-Apr
Released
2026-04-25
Last Updated
2026-05-06
EPSS Score
0.36% (percentile: 28.6%)

Affected Products (3)

Other

  • 21311-17084

Open Source Software

  • azl3 python-mako 1.2.4-2 on Azure Linux 3.0
  • cbl2 python-mako 1.2.2-2 on CBL Mariner 2.0

Revision History

  • 2026-04-25: Information published.
  • 2026-04-26: Information published.
  • 2026-04-27: Information published.
  • 2026-05-06: Information published.
  • 2026-05-06: Information published.