Tuesday, May 5, 2026

[USN-8234-1] Mako vulnerability

========================================================================== Ubuntu Security Notice USN-8234-1 May 05, 2026 python-mako vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS - Ubuntu 25.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS Summary: Mako could be made to expose sensitive information over the network. Software Description: - mako: fast and lightweight templating for the Python platform Details: It was discovered that Mako incorrectly handled URIs with double-slash prefixes in TemplateLookup. A remote attacker could possibly use this issue to obtain sensitive information. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS python3-mako 1.3.10-3ubuntu0.1 Ubuntu 25.10 python3-mako 1.3.9-1ubuntu0.1 Ubuntu 24.04 LTS python3-mako 1.3.2-1ubuntu0.1 Ubuntu 22.04 LTS python3-mako 1.1.3+ds1-2ubuntu0.2 Ubuntu 20.04 LTS python-mako 1.1.0+ds1-1ubuntu2.1+esm1 Available with Ubuntu Pro python3-mako 1.1.0+ds1-1ubuntu2.1+esm1 Available with Ubuntu Pro Ubuntu 18.04 LTS python-mako 1.0.7+ds1-1ubuntu0.2+esm1 Available with Ubuntu Pro python3-mako 1.0.7+ds1-1ubuntu0.2+esm1 Available with Ubuntu Pro Ubuntu 16.04 LTS python-mako 1.0.3+ds1-1ubuntu1+esm2 Available with Ubuntu Pro python3-mako 1.0.3+ds1-1ubuntu1+esm2 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8234-1 CVE-2026-41205 Package Information: https://launchpad.net/ubuntu/+source/mako/1.3.10-3ubuntu0.1 https://launchpad.net/ubuntu/+source/mako/1.3.9-1ubuntu0.1 https://launchpad.net/ubuntu/+source/mako/1.3.2-1ubuntu0.1 https://launchpad.net/ubuntu/+source/mako/1.1.3+ds1-2ubuntu0.2

No comments:

Post a Comment