Inefficient regular expression complexity in Sqlparse - CVE-2026-59893
Published: August 13, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to inefficient regular expression complexity in the dollar-quoted SQL literal lexer and multiline comment patterns when parsing user-supplied SQL text. A remote attacker can send specially crafted SQL input with unmatched dollar-quote delimiters or unterminated comment openers to cause a denial of service.
A single crafted request carrying SQL text is sufficient to trigger sustained CPU exhaustion.
Affected software
SUSE Linux Enterprise Server 15 SP6
SUSE Linux Enterprise Server 15 SP5
SUSE Linux Enterprise Server 15 SP4
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
Public Cloud Module
Basesystem Module
Python 3 Module
SUSE Package Hub 15
openSUSE Leap
Ubuntu
openEuler
sqlparse (Ubuntu package)
python2-sqlparse
python-sqlparse
python3-sqlparse
python-sqlparse-help
python311-sqlparse
python3.12-sqlparse (Red Hat package)
python-sqlparse (Red Hat package)
receptor (Red Hat package)
automation-controller-cli (Red Hat package)
Ansible Automation Platform
How to mitigate CVE-2026-59893
sqlparse (Ubuntu package) - addressed in versions 0.1.18-1ubuntu0.1~esm1, 0.2.4-0.1ubuntu0.1+esm1, 0.2.4-3ubuntu0.1+esm1, 0.4.2-1ubuntu0.22.04.3, 0.4.4-1ubuntu0.2, 0.5.4-1ubuntu0.1
python2-sqlparse - update to 0.2.4-150100.6.11.1
python-sqlparse - update to 0.4.2-4
python3-sqlparse - update to 0.4.2-4
python-sqlparse-help - update to 0.4.2-4
python3-sqlparse - update to 0.4.2-150300.23.1
python311-sqlparse - addressed in versions 0.4.4-150400.6.16.1, 0.4.4-150600.3.9.1
python3.12-sqlparse (Red Hat package) - update to 0.6.0-1.el9ap
python-sqlparse (Red Hat package) - update to 0.6.0-1.el10ap
receptor (Red Hat package) - addressed in versions 1.6.8-1.el9ap, 1.6.8-1.el10ap
Ansible Automation Platform - update to 2.7
automation-controller-cli (Red Hat package) - addressed in versions 4.8.9-1.el9ap, 4.8.9-1.el10ap