Inefficient Algorithmic Complexity in Sqlparse - CVE-2026-54284

 

Inefficient Algorithmic Complexity in Sqlparse - CVE-2026-54284

Published: August 13, 2026


Vulnerability identifier: #VU142416
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-54284
CWE-ID: CWE-407
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to inefficient algorithmic complexity in TokenList.__init__ when parsing attacker-supplied SQL with deeply nested grouping constructs. A remote attacker can send a specially crafted SQL input to cause a denial of service.

The issue is reachable through the default sqlparse.parse, sqlparse.format, and sqlparse.split entry points, and nested parentheses, nested CASE WHEN expressions, nested subqueries, or nested ARRAY[] literals can trigger excessive CPU consumption before parser depth and token caps raise an error.


Affected software

Sqlparse
SUSE Linux Enterprise Server 15 SP6
SUSE Linux Enterprise Server 15 SP5
SUSE Linux Enterprise Server 15 SP4
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
Public Cloud Module
Python 3 Module
Basesystem Module
SUSE Package Hub 15
openSUSE Leap
Ubuntu
openEuler
sqlparse (Ubuntu package)
python2-sqlparse
python3-sqlparse
python311-sqlparse
python-sqlparse
python3.12-sqlparse (Red Hat package)
python-sqlparse (Red Hat package)
receptor (Red Hat package)
automation-controller-cli (Red Hat package)
Ansible Automation Platform

How to mitigate CVE-2026-54284

Install security update from vendor's website.

Sqlparse - update to 0.6.0
sqlparse (Ubuntu package) - addressed in versions 0.1.18-1ubuntu0.1~esm1, 0.2.4-0.1ubuntu0.1+esm1, 0.2.4-3ubuntu0.1+esm1, 0.4.2-1ubuntu0.22.04.3, 0.4.4-1ubuntu0.2, 0.5.4-1ubuntu0.1
python2-sqlparse - update to 0.2.4-150100.6.11.1
python3-sqlparse - update to 0.4.2-150300.23.1
python311-sqlparse - addressed in versions 0.4.4-150400.6.16.1, 0.4.4-150600.3.9.1
python3-sqlparse - update to 0.6.0-1
python-sqlparse - update to 0.6.0-1
python3.12-sqlparse (Red Hat package) - update to 0.6.0-1.el9ap
python-sqlparse (Red Hat package) - update to 0.6.0-1.el10ap
receptor (Red Hat package) - addressed in versions 1.6.8-1.el9ap, 1.6.8-1.el10ap
Ansible Automation Platform - update to 2.7
automation-controller-cli (Red Hat package) - addressed in versions 4.8.9-1.el9ap, 4.8.9-1.el10ap

External References

Related Security Bulletins