šŸ” CVE Alert

CVE-2026-71491

UNKNOWN 0.0

sqlparse: Quadratic O(n²) DoS in group_comments

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

sqlparse is a non-validating SQL parser module for Python. Prior to 0.6.0, group_comments in sqlparse/engine/grouping.py repeatedly rescans comment-only statements before the MAX_GROUPING_TOKENS guard, causing quadratic CPU consumption through sqlparse.parse() and sqlparse.format(sql, strip_comments=True). This issue is fixed in version 0.6.0.

CWE CWE-400 CWE-407
Vendor andialbrecht
Product sqlparse
Published Aug 17, 2026
Last Updated Aug 17, 2026
Stay Ahead of the Next One

Get instant alerts for andialbrecht sqlparse

Be the first to know when new unknown vulnerabilities affecting andialbrecht sqlparse are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free Ā· No credit card Ā· 60 sec setup

Affected Versions

andialbrecht / sqlparse
< 0.6.0

References

NVD ↗ CVE.org ↗ EPSS Data ↗
github.com: https://github.com/andialbrecht/sqlparse/security/advisories/GHSA-f2ff-p2ww-7p4p github.com: https://github.com/andialbrecht/sqlparse/commit/ef2012a5eeb491e604dea2b00d516904a3830c87