Resource exhaustion in Sqlparse - CVE-2026-84305

 

Resource exhaustion in Sqlparse - CVE-2026-84305

Published: August 13, 2026 / Updated: September 2, 2026


Vulnerability identifier: #VU142414
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-84305
CWE-ID: CWE-400
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to uncontrolled resource consumption in ReindentFilter when formatting attacker-controlled SQL with reindentation enabled. A remote attacker can supply a specially crafted parenthesized tuple-list input to cause a denial of service.

The issue is reachable through sqlparse.format(sql, reindent=True) and the sqlformat --reindent mode.


Affected software

Sqlparse
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
Public Cloud Module
SUSE Package Hub 15
Python 3 Module
openSUSE Leap
python2-sqlparse
python311-sqlparse

How to mitigate CVE-2026-84305

Install security update from vendor's website.

Sqlparse - update to 0.6.0
python2-sqlparse - update to 0.2.4-150100.6.14.1
python311-sqlparse - update to 0.4.4-150600.3.12.1

External References

Related Security Bulletins