Sqlparse
10 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Sqlparse, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
Sqlparse CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 1 |
| 2026-03 | 0 |
| 2026-04 | 0 |
| 2026-05 | 0 |
| 2026-06 | 1 |
| 2026-07 | 0 |
| 2026-08 | 4 |
| 2026-09 | 1 |
Severity
How the 10 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- High3
- Medium2
Latest CVEs
The 10 most recently published vulnerabilities affecting Sqlparse.
- CVE-2026-84305sqlparse: Reindentation of tuple lists causes near-cap quadratic CPU consumption—
- CVE-2026-54284sqlparse: TokenList.__init__ materializes O(subtree) value per group, causing CPU DoS before depth/token caps trigger—
- CVE-2026-59893sqlparse: Inefficient Regex Handling of Dollar-Quoted SQL Literals Leads to ReDoS (Denial of Service)7.5
- CVE-2026-71491sqlparse: Quadratic O(n²) DoS in group_comments—
- CVE-2026-59894sqlparse: Generated Python and PHP snippets allow SQL string breakout through unescaped backslashes—
- BDU:2026-07974Уязвимость функционала форматирования модуля парсера SQL для Python Sqlparse, позволяющая нарушителю вызвать отказ в обслуживании5.3
- GHSA-27jp-wm6q-gp25sqlparse: formatting list of tuples leads to denial of service—
- CVE-2024-4340Passing a heavily nested list to sqlparse.parse() leads to a Denial of Service due to RecursionError.7.5
- CVE-2023-30608Parser contains an inefficient regular expression in sqlparse5.5
- CVE-2021-32839Regular Expression Denial of Service in sqlparse7.5
Product grouping is registry-driven, with AI assist and human review. How it works