Resource exhaustion in Sqlparse - CVE-2026-71491
Published: August 13, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to uncontrolled resource consumption in the group_comments function when parsing a comment-only SQL statement. A remote attacker can supply many single-line comments to consume excessive CPU resources and cause a denial of service.
The issue is reachable via sqlparse.parse() and sqlparse.format(sql, strip_comments=true), and the quadratic cost is incurred before the token-count guard is applied.
Affected software
SUSE Linux Enterprise Server 15 SP6
SUSE Linux Enterprise Server 15 SP5
SUSE Linux Enterprise Server 15 SP4
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
Public Cloud Module
Python 3 Module
Basesystem Module
SUSE Package Hub 15
openSUSE Leap
Ubuntu
openEuler
sqlparse (Ubuntu package)
python2-sqlparse
python3-sqlparse
python311-sqlparse
python-sqlparse
python3.12-sqlparse (Red Hat package)
python-sqlparse (Red Hat package)
receptor (Red Hat package)
automation-controller-cli (Red Hat package)
Ansible Automation Platform
How to mitigate CVE-2026-71491
sqlparse (Ubuntu package) - addressed in versions 0.1.18-1ubuntu0.1~esm1, 0.2.4-0.1ubuntu0.1+esm1, 0.2.4-3ubuntu0.1+esm1, 0.4.2-1ubuntu0.22.04.3, 0.4.4-1ubuntu0.2, 0.5.4-1ubuntu0.1
python2-sqlparse - update to 0.2.4-150100.6.11.1
python3-sqlparse - update to 0.4.2-150300.23.1
python311-sqlparse - addressed in versions 0.4.4-150400.6.16.1, 0.4.4-150600.3.9.1
python3-sqlparse - update to 0.6.0-1
python-sqlparse - update to 0.6.0-1
python3.12-sqlparse (Red Hat package) - update to 0.6.0-1.el9ap
python-sqlparse (Red Hat package) - update to 0.6.0-1.el10ap
receptor (Red Hat package) - addressed in versions 1.6.8-1.el9ap, 1.6.8-1.el10ap
Ansible Automation Platform - update to 2.7
automation-controller-cli (Red Hat package) - addressed in versions 4.8.9-1.el9ap, 4.8.9-1.el10ap
External References
Related Security Bulletins
- Multiple vulnerabilities in Sqlparse
- SUSE update for python-sqlparse
- SUSE update for python3-sqlparse
- SUSE update for python-sqlparse
- SUSE update for python-sqlparse
- Multiple vulnerabilities in Ansible Automation Platform 2.7 packages
- Ubuntu update for sqlparse
- openEuler 24.03 LTS SP4 update for python-sqlparse
- openEuler 24.03 LTS SP3 update for python-sqlparse