Source: sqlparse Version: 0.5.5-2 Severity: important Tags: security upstream X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi, The following vulnerabilities were published for sqlparse. CVE-2026-54284[0]: | sqlparse is a non-validating SQL parser module for Python. Prior to | 0.6.0, TokenList construction and string conversion in | sqlparse/sql.py repeatedly flatten nested token subtrees constructed | by group_parenthesis and group_case, causing quadratic CPU | consumption through sqlparse.parse(), sqlparse.format(), and | sqlparse.split() before depth and token limits terminate processing. | This issue is fixed in version 0.6.0. CVE-2026-59893[1]: | sqlparse is a non-validating SQL parser module for Python. Prior to | 0.6.0, SQL_REGEX in sqlparse/keywords.py and the per-position loop | in sqlparse/lexer.py repeatedly scan unmatched dollar-quoted literal | and multiline-comment delimiters, causing quadratic CPU consumption | through sqlparse.parse(), sqlparse.format(), and sqlparse.split(). | This issue is fixed in version 0.6.0. CVE-2026-59894[2]: | sqlparse is a non-validating SQL parser module for Python. Prior to | 0.6.0, sqlparse/filters/output.py fails to escape existing | backslashes before quotes in sqlparse.format output_format='python' | and output_format='php' and the corresponding sqlformat -l modes, | allowing crafted SQL to terminate the generated string and inject | Python or PHP code when a downstream consumer executes or imports | the generated source. This issue is fixed in version 0.6.0. CVE-2026-71491[3]: | sqlparse is a non-validating SQL parser module for Python. Prior to | 0.6.0, group_comments in sqlparse/engine/grouping.py repeatedly | rescans comment-only statements before the MAX_GROUPING_TOKENS | guard, causing quadratic CPU consumption through sqlparse.parse() | and sqlparse.format(sql, strip_comments=True). This issue is fixed | in version 0.6.0. If you fix the vulnerabilities please also make sure to include the CVE (Common Vulnerabilities & Exposures) ids in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-54284 https://www.cve.org/CVERecord?id=CVE-2026-54284 [1] https://security-tracker.debian.org/tracker/CVE-2026-59893 https://www.cve.org/CVERecord?id=CVE-2026-59893 [2] https://security-tracker.debian.org/tracker/CVE-2026-59894 https://www.cve.org/CVERecord?id=CVE-2026-59894 [3] https://security-tracker.debian.org/tracker/CVE-2026-71491 https://www.cve.org/CVERecord?id=CVE-2026-71491 Regards, Salvatore

