VAITP Dataset

← Back to the dataset

CVE-2026-54284

sqlparse is vulnerable to denial of service via quadratic CPU consumption.

  • CVSS 8.7
  • 407
  • Resource Management
  • Remote

sqlparse is a non-validating SQL parser module for Python. Prior to 0.6.0, TokenList construction and string conversion in sqlparse/sql.py repeatedly flatten nested token subtrees constructed by group_parenthesis and group_case, causing quadratic CPU consumption through sqlparse.parse(), sqlparse.format(), and sqlparse.split() before depth and token limits terminate processing. This issue is fixed in version 0.6.0.

CWE
407
CVSS base score
8.7
Published
2026-08-17
OWASP
A04 Insecure Design
Orthogonal defect classification
Algorithm
Code defect classification
Incorrect Algorithm
Category
Resource Management
Subcategory
Resource Exhaustion
Accessibility scope
Remote
Impact
Denial of Service (DoS)
Affected component
sqlparse
Fixed by upgrading
Yes

Solution

Upgrade `sqlparse` to version 0.6.0 or later.

Vulnerable code sample

import collections

# Simplified Token representation for demonstration, based on sqlparse's structure.
class Token(collections.namedtuple('Token', 'ttype value')):
    is_group = False

    def __str__(self):
        return str(self.value)

    def flatten(self):
        yield self


class TokenList:
    """A group of tokens, representing a part of a SQL statement."""

    def __init__(self, tokens=None):
        self.tokens = tokens or []

    @property
    def is_group(self):
        return True

    def flatten(self):
        """Generator yielding tokens and sub-tokens."""
        for token in self.tokens:
            if token.is_group:
                # In Python 3.3+ 'yield from' is possible
                for t in token.flatten():
                    yield t
            else:
                yield token

    # VULNERABLE: Repeatedly flattens nested token subtrees, causing quadratic complexity.
    def __str__(self):
        return ''.join(str(token) for token in self.flatten())

Patched code sample

import collections

# Simplified Token representation for demonstration, based on sqlparse's structure.
class Token(collections.namedtuple('Token', 'ttype value')):
    is_group = False

    def __str__(self):
        return str(self.value)

    def flatten(self):
        yield self


class TokenList:
    """A group of tokens, representing a part of a SQL statement."""

    def __init__(self, tokens=None):
        self.tokens = tokens or []

    @property
    def is_group(self):
        return True

    def flatten(self):
        """Generator yielding tokens and sub-tokens."""
        for token in self.tokens:
            if token.is_group:
                # In Python 3.3+ 'yield from' is possible
                for t in token.flatten():
                    yield t
            else:
                yield token

    # FIX: Avoids repeated flattening by directly iterating over immediate children.
    def __str__(self):
        return ''.join(str(token) for token in self.tokens)

Payload

__VAITP_MODEL_REFUSED__

Cite this entry

@misc{vaitp:cve202654284,
  title        = {{sqlparse is vulnerable to denial of service via quadratic CPU consumption.}},
  author       = {Bogaerts, Fr\'ed\'eric and Ivaki, Naghmeh and Fonseca, Jos\'e},
  year         = {2026},
  note         = {VAITP Python Vulnerability Dataset, entry CVE-2026-54284},
  howpublished = {\url{https://netpack.pt/vaitp/vulnerability/CVE-2026-54284/}}
}
Introducing the "VAITP dataset": a specialized repository of Python vulnerabilities and patches, meticulously compiled for the use of the security research community. As Python's prominence grows, understanding and addressing potential security vulnerabilities become crucial. Crafted by and for the cybersecurity community, this dataset offers a valuable resource for researchers, analysts, and developers to analyze and mitigate the security risks associated with Python. Through the comprehensive exploration of vulnerabilities and corresponding patches, the VAITP dataset fosters a safer and more resilient Python ecosystem, encouraging collaborative advancements in programming security.

The supreme art of war is to subdue the enemy without fighting.

Sun Tzu – “The Art of War”

:: Shaping the future through research and ingenuity ::