Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
PYSEC-2026-3923
  • PyPI/sqlparse
sqlparse: Reindentation of tuple lists causes near-cap quadratic CPU consumption 10 Sep
  • Fix available
  • Severity - 5.1 (Medium)
GHSA-cfqr-cjx5-5jcm
  • PyPI/sqlparse
sqlparse: Reindentation of tuple lists causes near-cap quadratic CPU consumption 01 Sep
  • Fix available
  • Severity - 5.1 (Medium)
PYSEC-2026-3698
  • PyPI/sqlparse
sqlparse: Inefficient Regex Handling of Dollar-Quoted SQL Literals Leads to ReDoS (Denial of Service) 19 Aug
  • Fix available
  • Severity - 7.5 (High)
PYSEC-2026-3699
  • PyPI/sqlparse
sqlparse: TokenList.__init__ materializes O(subtree) value per group, causing CPU DoS before depth/token caps trigger 19 Aug
  • Fix available
  • Severity - 8.7 (High)
PYSEC-2026-3697
  • PyPI/sqlparse
sqlparse: Quadratic O(n²) DoS in group_comments 19 Aug
  • Fix available
  • Severity - 8.7 (High)
PYSEC-2026-3696
  • PyPI/sqlparse
sqlparse: Generated Python and PHP snippets allow SQL string breakout through unescaped backslashes 19 Aug
  • Fix available
  • Severity - 6.2 (Medium)
GHSA-prg7-hcfm-mfcr
  • PyPI/sqlparse
sqlparse: Inefficient Regex Handling of Dollar-Quoted SQL Literals Leads to ReDoS (Denial of Service) 17 Aug
  • Fix available
  • Severity - 7.5 (High)
GHSA-pwgv-4x5q-6m9f
  • PyPI/sqlparse
sqlparse: TokenList.__init__ materializes O(subtree) value per group, causing CPU DoS before depth/token caps trigger 17 Aug
  • Fix available
  • Severity - 8.7 (High)
GHSA-f2ff-p2ww-7p4p
  • PyPI/sqlparse
sqlparse: Quadratic O(n²) DoS in group_comments 17 Aug
  • Fix available
  • Severity - 8.7 (High)
GHSA-3496-9g83-7v6x
  • PyPI/sqlparse
sqlparse: Generated Python and PHP snippets allow SQL string breakout through unescaped backslashes 17 Aug
  • Fix available
  • Severity - 6.2 (Medium)
PYSEC-2026-1940
  • PyPI/sqlparse
sqlparse parsing heavily nested list leads to Denial of Service 07 Jul
  • Fix available
  • Severity - 7.5 (High)
GHSA-27jp-wm6q-gp25
  • PyPI/sqlparse
sqlparse: formatting list of tuples leads to denial of service 13 Feb
  • Fix available
  • Severity - 6.9 (Medium)
GHSA-2m57-hf25-phgg
  • PyPI/sqlparse
sqlparse parsing heavily nested list leads to Denial of Service 15 Apr 2024
  • Fix available
  • Severity - 7.5 (High)
GHSA-rrm6-wvj7-cwh2
  • PyPI/sqlparse
sqlparse contains a regular expression that is vulnerable to Regular Expression Denial of Service 21 Apr 2023
  • Fix available
  • Severity - 6.9 (Medium)
PYSEC-2023-87
  • PyPI/sqlparse
  • github.com/andialbrecht/sqlparse
See record for full details 18 Apr 2023
  • Fix available
PYSEC-2021-333
  • PyPI/sqlparse
  • github.com/andialbrecht/sqlparse
See record for full details 20 Sep 2021
  • Fix available