{"id":"CVE-2026-59893","title":"sqlparse is a non-validating SQL parser module for Python","summary":"sqlparse is a non-validating SQL parser module for Python. Prior to 0.6.0, SQL_REGEX in sqlparse/keywords.py and the per-position loop in sqlparse/lexer.py repeatedly scan unmatched dollar-quoted literal and multiline-comment delimiters,…","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":["CWE-1333"],"vendor":"sqlparse","product":"sqlparse","affected":["sqlparse < 0.6.0"],"patched":["sqlparse 0.6.0"],"published":"2026-08-17","updated":"2026-09-18","sourceUpdated":"2026-09-18T20:09:01.757","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-59893","references":[{"url":"https://github.com/andialbrecht/sqlparse/commit/d1d80602741f77ec78e5a04ce4719244cf32352e","label":"security-advisories@github.com"},{"url":"https://github.com/andialbrecht/sqlparse/security/advisories/GHSA-prg7-hcfm-mfcr","label":"security-advisories@github.com"},{"url":"https://github.com/andialbrecht/sqlparse/security/advisories/GHSA-prg7-hcfm-mfcr","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"url":"https://github.com/andialbrecht/sqlparse"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-59893.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-59893"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2517523"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-59893"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-59893"},{"url":"https://access.redhat.com/errata/RHSA-2026:61783"},{"url":"https://github.com/advisories/GHSA-prg7-hcfm-mfcr"},{"url":"https://access.redhat.com/errata/RHSA-2026:67279"},{"url":"https://access.redhat.com/errata/RHSA-2026:69539"}],"tags":["nvd","osv","pip","csaf","vex","red-hat","ghsa"],"epss":0.00279,"epssPercentile":0.20615,"aliases":["GHSA-prg7-hcfm-mfcr","PYSEC-2026-3698"],"ecosystem":"pip","ingestedAt":"2026-08-17T17:58:10.140Z","slug":"CVE-2026-59893","body":"## Overview\n\nsqlparse is a non-validating SQL parser module for Python. Prior to 0.6.0, SQL_REGEX in sqlparse/keywords.py and the per-position loop in sqlparse/lexer.py repeatedly scan unmatched dollar-quoted literal and multiline-comment delimiters, causing quadratic CPU consumption through sqlparse.parse(), sqlparse.format(), and sqlparse.split(). This issue is fixed in version 0.6.0.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Package advisory (CVE-2026-59893)\n\nAffected packages:\n\n- `sqlparse < 0.6.0`\n\nPatched in:\n\n- `sqlparse 0.6.0`\n\nSource: https://osv.dev/vulnerability/GHSA-prg7-hcfm-mfcr\n\n## Vendor advisories\n\n- **RHSA-2026:61783** · Red Hat · fixed in: Red Hat Discovery 2 · released 2026-08-31 · [advisory](https://access.redhat.com/errata/RHSA-2026:61783)\n- **Red Hat VEX** · Important · affected: Red Hat Ansible Automation Platform 2, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift Container Platform 4, Red Hat OpenStack Platform 16.2, Red Hat OpenStack Platform 17.1, Red Hat OpenStack Platform 18.0, … · no fix planned: Red Hat Ansible Automation Platform 2, Red Hat Update Infrastructure 4 for Cloud Providers, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift Container Platform 4, … · updated 2026-09-22 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-59893.json)\n- **RHSA-2026:67279** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.7 · released 2026-09-14 · [advisory](https://access.redhat.com/errata/RHSA-2026:67279)\n- **RHSA-2026:69539** · Red Hat · fixed in: Red Hat OpenShift AI 3.5 · released 2026-09-21 · [advisory](https://access.redhat.com/errata/RHSA-2026:69539)","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}