CVE-2026-71491
sqlparse: Quadratic O(n²) DoS in group_comments
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
sqlparse is a non-validating SQL parser module for Python. Prior to 0.6.0, group_comments in sqlparse/engine/grouping.py repeatedly rescans comment-only statements before the MAX_GROUPING_TOKENS guard, causing quadratic CPU consumption through sqlparse.parse() and sqlparse.format(sql, strip_comments=True). This issue is fixed in version 0.6.0.
| CWE | CWE-400 CWE-407 |
| Vendor | andialbrecht |
| Product | sqlparse |
| Published | Aug 17, 2026 |
| Last Updated | Aug 17, 2026 |
Stay Ahead of the Next One
Get instant alerts for andialbrecht sqlparse
Be the first to know when new unknown vulnerabilities affecting andialbrecht sqlparse are published ā delivered to Slack, Telegram or Discord.
Get Free Alerts ā
Free Ā· No credit card Ā· 60 sec setup
Affected Versions
andialbrecht / sqlparse
< 0.6.0