CVE-2026-54284

sqlparse is a non-validating SQL parser module for Python. Prior to 0.6.0, TokenList construction and string conversion in sqlparse/sql.py repeatedly flatten nested token subtrees constructed by group_parenthesis and group_case, causing quadratic CPU consumption through sqlparse.parse(), sqlparse.format(), and sqlparse.split() before depth and token limits terminate processing. This issue is fixed in version 0.6.0.
CVSS

No CVSS.

Configurations

No configuration.

History

No history.

Information

Published : 2026-08-17 18:17

Updated : 2026-08-17 20:16


NVD link : CVE-2026-54284

Mitre link : CVE-2026-54284

CVE.ORG link : CVE-2026-54284


JSON object : View

Products Affected

No product.

CWE
CWE-407

Inefficient Algorithmic Complexity

CWE-1333

Inefficient Regular Expression Complexity