CVE-2026-54284
sqlparse is vulnerable to denial of service via quadratic CPU consumption.
- CVSS 8.7
- 407
- Resource Management
- Remote
sqlparse is a non-validating SQL parser module for Python. Prior to 0.6.0, TokenList construction and string conversion in sqlparse/sql.py repeatedly flatten nested token subtrees constructed by group_parenthesis and group_case, causing quadratic CPU consumption through sqlparse.parse(), sqlparse.format(), and sqlparse.split() before depth and token limits terminate processing. This issue is fixed in version 0.6.0.
- CWE
- 407
- CVSS base score
- 8.7
- Published
- 2026-08-17
- OWASP
- A04 Insecure Design
- Orthogonal defect classification
- Algorithm
- Code defect classification
- Incorrect Algorithm
- Category
- Resource Management
- Subcategory
- Resource Exhaustion
- Accessibility scope
- Remote
- Impact
- Denial of Service (DoS)
- Affected component
- sqlparse
- Fixed by upgrading
- Yes
Solution
Upgrade `sqlparse` to version 0.6.0 or later.
Vulnerable code sample
import collections
# Simplified Token representation for demonstration, based on sqlparse's structure.
class Token(collections.namedtuple('Token', 'ttype value')):
is_group = False
def __str__(self):
return str(self.value)
def flatten(self):
yield self
class TokenList:
"""A group of tokens, representing a part of a SQL statement."""
def __init__(self, tokens=None):
self.tokens = tokens or []
@property
def is_group(self):
return True
def flatten(self):
"""Generator yielding tokens and sub-tokens."""
for token in self.tokens:
if token.is_group:
# In Python 3.3+ 'yield from' is possible
for t in token.flatten():
yield t
else:
yield token
# VULNERABLE: Repeatedly flattens nested token subtrees, causing quadratic complexity.
def __str__(self):
return ''.join(str(token) for token in self.flatten())Patched code sample
import collections
# Simplified Token representation for demonstration, based on sqlparse's structure.
class Token(collections.namedtuple('Token', 'ttype value')):
is_group = False
def __str__(self):
return str(self.value)
def flatten(self):
yield self
class TokenList:
"""A group of tokens, representing a part of a SQL statement."""
def __init__(self, tokens=None):
self.tokens = tokens or []
@property
def is_group(self):
return True
def flatten(self):
"""Generator yielding tokens and sub-tokens."""
for token in self.tokens:
if token.is_group:
# In Python 3.3+ 'yield from' is possible
for t in token.flatten():
yield t
else:
yield token
# FIX: Avoids repeated flattening by directly iterating over immediate children.
def __str__(self):
return ''.join(str(token) for token in self.tokens)Payload
__VAITP_MODEL_REFUSED__
Cite this entry
@misc{vaitp:cve202654284,
title = {{sqlparse is vulnerable to denial of service via quadratic CPU consumption.}},
author = {Bogaerts, Fr\'ed\'eric and Ivaki, Naghmeh and Fonseca, Jos\'e},
year = {2026},
note = {VAITP Python Vulnerability Dataset, entry CVE-2026-54284},
howpublished = {\url{https://netpack.pt/vaitp/vulnerability/CVE-2026-54284/}}
}
Introducing the "VAITP dataset": a specialized repository of Python vulnerabilities and patches, meticulously compiled for the use of the security research community. As Python's prominence grows, understanding and addressing potential security vulnerabilities become crucial. Crafted by and for the cybersecurity community, this dataset offers a valuable resource for researchers, analysts, and developers to analyze and mitigate the security risks associated with Python. Through the comprehensive exploration of vulnerabilities and corresponding patches, the VAITP dataset fosters a safer and more resilient Python ecosystem, encouraging collaborative advancements in programming security.
The supreme art of war is to subdue the enemy without fighting.
Sun Tzu – “The Art of War”
:: Shaping the future through research and ingenuity ::
