{"id":"CVE-2026-59894","title":"sqlparse is a non-validating SQL parser module for Python","summary":"sqlparse is a non-validating SQL parser module for Python. Prior to 0.6.0, sqlparse/filters/output.py fails to escape existing backslashes before quotes in sqlparse.format output_format='python' and output_format='php' and the correspond…","severity":"medium","cwe":["CWE-94"],"vendor":"sqlparse","product":"sqlparse","affected":["sqlparse < 0.6.0"],"patched":["sqlparse 0.6.0"],"published":"2026-08-17","updated":"2026-09-18","sourceUpdated":"2026-09-18T20:09:01.757","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-59894","references":[{"url":"https://github.com/andialbrecht/sqlparse/security/advisories/GHSA-3496-9g83-7v6x","label":"security-advisories@github.com"},{"url":"https://github.com/andialbrecht/sqlparse/commit/53ff44b53e27cff78259acc1af015506fea60f63"},{"url":"https://github.com/andialbrecht/sqlparse"},{"url":"https://github.com/advisories/GHSA-3496-9g83-7v6x"}],"tags":["nvd","osv","pip","ghsa"],"epss":0.00129,"epssPercentile":0.02882,"aliases":["GHSA-3496-9g83-7v6x","PYSEC-2026-3696"],"ecosystem":"pip","ingestedAt":"2026-08-17T17:58:11.065Z","slug":"CVE-2026-59894","body":"## Overview\n\nsqlparse is a non-validating SQL parser module for Python. Prior to 0.6.0, sqlparse/filters/output.py fails to escape existing backslashes before quotes in sqlparse.format output_format='python' and output_format='php' and the corresponding sqlformat -l modes, allowing crafted SQL to terminate the generated string and inject Python or PHP code when a downstream consumer executes or imports the generated source. This issue is fixed in version 0.6.0.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Package advisory (CVE-2026-59894)\n\nAffected packages:\n\n- `sqlparse < 0.6.0`\n\nPatched in:\n\n- `sqlparse 0.6.0`\n\nSource: https://osv.dev/vulnerability/GHSA-3496-9g83-7v6x","depth":"sunlit","depthScore":28,"depthScoreParts":{"impact":27.5,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}