FlawAtlas
Search the atlas
CVE-2019-7164 Critical

CVE-2019-7164

SQLAlchemy before 1.3.0b3 allows SQL Injection via the order_by parameter. The fix (commit 30307c4) was applied only to the main branch and was never backported to the 1.2.x release line; all 1.2.x versions remain vulnerable.

Exploit probability 3.5%
Published February 20, 2019
Required by Not available
Last source change June 9, 2026

02 / AFFECTED SOFTWARE

Affected packages

Unknown Unknown

112 explicit affected versions

PyPI sqlalchemy

178 explicit affected versions

PyPI sqlalchemy

178 explicit affected versions

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities CVE-2019-7164

SQLAlchemy through 1.2.17 and 1.3.x through 1.3.0b2 allows SQL Injection via the order_by parameter.

View original source
Open Source Vulnerabilities PYSEC-2019-123

SQLAlchemy before 1.3.0b3 allows SQL Injection via the order_by parameter. The fix (commit 30307c4) was applied only to the main branch and was never backported to the 1.2.x release line; all 1.2.x versions remain vulnerable.

View original source
Open Source Vulnerabilities GHSA-887w-45rq-vxgf

SQLAlchemy before 1.3.0b3 allows SQL Injection via the order_by parameter. The fix (commit 30307c4) was applied only to the main branch and was never backported to the 1.2.x release line; all 1.2.x versions remain vulnerable.

View original source

05 / REFERENCES

Further evidence