SQLAlchemy is a widely embedded Python ORM and SQL toolkit that abstracts database interaction across many web applications and services, making its security profile matter broadly despite a narrow direct product scope. The durable signal centers on input-handling and query-construction weaknesses such as SQL injection, path traversal, and inefficient regex complexity, reflecting the parsing demands of dynamic query generation; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Sqlalchemy over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-7164CRITICAL SQLAlchemy through 1.2.17 and 1.3.x through 1.3.0b2 allows SQL Injection via the order_by parameter. | Feb 20, 2019 | 9.8 | 27 | NO | NO |
CVE-2026-41205HIGH Mako is a template library written in Python. Prior to 1.3.11, TemplateLookup.get_template() is vulnerable to path traversal when a URI starts with // (e.g., //../../../secret.txt) | Apr 23, 2026 | 7.5 | 26 | NO | NO |
CVE-2022-40023HIGH Sqlalchemy mako before 1.2.2 is vulnerable to Regular expression Denial of Service when using the Lexer class to parse. This also affects babelplugin and linguaplugin. | Sep 7, 2022 | 7.5 | 26 | NO | NO |
CVE-2019-7548HIGH SQLAlchemy 1.2.17 has SQL Injection when the group_by parameter can be controlled. | Feb 6, 2019 | 7.8 | 26 | NO | NO |
CVE-2012-0805HIGH Multiple SQL injection vulnerabilities in SQLAlchemy before 0.7.0b4, as used in Keystone, allow remote attackers to execute arbitrary SQL commands via the (1) limit or (2) offset k | Jun 5, 2012 | 7.5 | 25 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Sqlalchemy.
Media articles that mention a CVE ID that affects a product developed by Sqlalchemy — matched by CVE ID, not by vendor name.