CVE-2026-41205: Mako: Path traversal via double-slash URI prefix in TemplateLookup

Overview

Severity
N/A
Exploit Status
Not Exploited
Patch Tuesday
2026-Apr
Released
2026-04-25
Last Updated
2026-04-27
EPSS Score
0.09% (percentile: 26.1%)

Affected Products (2)

Open Source Software

  • azl3 python-mako 1.2.4-2 on Azure Linux 3.0
  • cbl2 python-mako 1.2.2-2 on CBL Mariner 2.0

Revision History

  • 2026-04-25: Information published.
  • 2026-04-26: Information published.
  • 2026-04-27: Information published.