Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-54284

Опубликовано: 17 авг. 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

sqlparse is a non-validating SQL parser module for Python. Prior to 0.6.0, TokenList construction and string conversion in sqlparse/sql.py repeatedly flatten nested token subtrees constructed by group_parenthesis and group_case, causing quadratic CPU consumption through sqlparse.parse(), sqlparse.format(), and sqlparse.split() before depth and token limits terminate processing. This issue is fixed in version 0.6.0.

A flaw was found in sqlparse, a Python module for parsing SQL. A remote attacker could exploit a vulnerability in the TokenList construction and string conversion processes, specifically when handling nested token subtrees. This flaw leads to quadratic CPU consumption, which can result in a Denial of Service (DoS) by exhausting system resources before internal limits are reached.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Ansible Automation Platform 2ansible-automation-platform-24/controller-rhel8Will not fix
Red Hat Ansible Automation Platform 2ansible-automation-platform-24/eda-controller-rhel8Not affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-24/hub-rhel8Affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-24/lightspeed-rhel8Will not fix
Red Hat Ansible Automation Platform 2ansible-automation-platform-25/ansible-dev-tools-rhel8Affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-25/controller-rhel8Affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-25/eda-controller-rhel8Affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-25/gateway-rhel8Affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-25/hub-rhel8Affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-25/lightspeed-rhel8Affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-1333
https://bugzilla.redhat.com/show_bug.cgi?id=2517527sqlparse: sqlparse: Denial of Service via quadratic CPU consumption in SQL parsing

EPSS

Процентиль: 18%
0.00263
Низкий

7.5 High

CVSS3

Связанные уязвимости

ubuntu
19 дней назад

sqlparse is a non-validating SQL parser module for Python. Prior to 0.6.0, TokenList construction and string conversion in sqlparse/sql.py repeatedly flatten nested token subtrees constructed by group_parenthesis and group_case, causing quadratic CPU consumption through sqlparse.parse(), sqlparse.format(), and sqlparse.split() before depth and token limits terminate processing. This issue is fixed in version 0.6.0.

nvd
19 дней назад

sqlparse is a non-validating SQL parser module for Python. Prior to 0.6.0, TokenList construction and string conversion in sqlparse/sql.py repeatedly flatten nested token subtrees constructed by group_parenthesis and group_case, causing quadratic CPU consumption through sqlparse.parse(), sqlparse.format(), and sqlparse.split() before depth and token limits terminate processing. This issue is fixed in version 0.6.0.

debian
19 дней назад

sqlparse is a non-validating SQL parser module for Python. Prior to 0. ...

github
19 дней назад

sqlparse: TokenList.__init__ materializes O(subtree) value per group, causing CPU DoS before depth/token caps trigger

suse-cvrf
7 дней назад

Security update for python-sqlparse

EPSS

Процентиль: 18%
0.00263
Низкий

7.5 High

CVSS3