Inefficient Algorithmic Complexity in Sqlparse - CVE-2026-54284
Published: August 13, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to inefficient algorithmic complexity in TokenList.__init__ when parsing attacker-supplied SQL with deeply nested grouping constructs. A remote attacker can send a specially crafted SQL input to cause a denial of service.
The issue is reachable through the default sqlparse.parse, sqlparse.format, and sqlparse.split entry points, and nested parentheses, nested CASE WHEN expressions, nested subqueries, or nested ARRAY[] literals can trigger excessive CPU consumption before parser depth and token caps raise an error.
Affected software
SUSE Linux Enterprise Server 15 SP6
SUSE Linux Enterprise Server 15 SP5
SUSE Linux Enterprise Server 15 SP4
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
Public Cloud Module
Python 3 Module
Basesystem Module
SUSE Package Hub 15
openSUSE Leap
Ubuntu
openEuler
sqlparse (Ubuntu package)
python2-sqlparse
python3-sqlparse
python311-sqlparse
python-sqlparse
python3.12-sqlparse (Red Hat package)
python-sqlparse (Red Hat package)
receptor (Red Hat package)
automation-controller-cli (Red Hat package)
Ansible Automation Platform
How to mitigate CVE-2026-54284
sqlparse (Ubuntu package) - addressed in versions 0.1.18-1ubuntu0.1~esm1, 0.2.4-0.1ubuntu0.1+esm1, 0.2.4-3ubuntu0.1+esm1, 0.4.2-1ubuntu0.22.04.3, 0.4.4-1ubuntu0.2, 0.5.4-1ubuntu0.1
python2-sqlparse - update to 0.2.4-150100.6.11.1
python3-sqlparse - update to 0.4.2-150300.23.1
python311-sqlparse - addressed in versions 0.4.4-150400.6.16.1, 0.4.4-150600.3.9.1
python3-sqlparse - update to 0.6.0-1
python-sqlparse - update to 0.6.0-1
python3.12-sqlparse (Red Hat package) - update to 0.6.0-1.el9ap
python-sqlparse (Red Hat package) - update to 0.6.0-1.el10ap
receptor (Red Hat package) - addressed in versions 1.6.8-1.el9ap, 1.6.8-1.el10ap
Ansible Automation Platform - update to 2.7
automation-controller-cli (Red Hat package) - addressed in versions 4.8.9-1.el9ap, 4.8.9-1.el10ap
External References
Related Security Bulletins
- Multiple vulnerabilities in Sqlparse
- SUSE update for python-sqlparse
- SUSE update for python3-sqlparse
- SUSE update for python-sqlparse
- SUSE update for python-sqlparse
- Multiple vulnerabilities in Ansible Automation Platform 2.7 packages
- Ubuntu update for sqlparse
- openEuler 24.03 LTS SP4 update for python-sqlparse
- openEuler 24.03 LTS SP3 update for python-sqlparse