{"id":"CVE-2026-71491","title":"sqlparse is a non-validating SQL parser module for Python","summary":"sqlparse is a non-validating SQL parser module for Python. Prior to 0.6.0, group_comments in sqlparse/engine/grouping.py repeatedly rescans comment-only statements before the MAX_GROUPING_TOKENS guard, causing quadratic CPU consumption t…","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":["CWE-400","CWE-407","CWE-1050"],"vendor":"Red Hat","product":"Red Hat OpenStack Platform 16.2","affected":["ansible_automation_platform 2","openshift_ai_rhoai","openshift_container_platform 4","openstack_platform 16.2","openstack_platform 17.1","openstack_platform 18.0","satellite 6","update_infrastructure_4_for_cloud_providers","update_infrastructure 5","self_service_automation_portal 2","discovery 2"],"patched":["discovery 2"],"published":"2026-08-17","updated":"2026-09-09","sourceUpdated":"2026-09-09T21:11:46.833","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-71491","references":[{"url":"https://github.com/andialbrecht/sqlparse/commit/ef2012a5eeb491e604dea2b00d516904a3830c87","label":"security-advisories@github.com"},{"url":"https://github.com/andialbrecht/sqlparse/security/advisories/GHSA-f2ff-p2ww-7p4p","label":"security-advisories@github.com"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-71491.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-71491"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2517518"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-71491"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-71491"},{"url":"https://access.redhat.com/errata/RHSA-2026:61783"},{"url":"https://github.com/advisories/GHSA-f2ff-p2ww-7p4p"},{"url":"https://github.com/andialbrecht/sqlparse"},{"url":"https://access.redhat.com/errata/RHSA-2026:67279"},{"url":"https://access.redhat.com/errata/RHSA-2026:69289"}],"tags":["nvd","csaf","vex","red-hat","ghsa","pip","osv"],"epss":0.00263,"epssPercentile":0.18398,"aliases":["GHSA-f2ff-p2ww-7p4p","PYSEC-2026-3697"],"ecosystem":"pip","cvssSource":"vendor","ingestedAt":"2026-08-17T17:58:10.919Z","slug":"CVE-2026-71491","body":"## Overview\n\nsqlparse is a non-validating SQL parser module for Python. Prior to 0.6.0, group_comments in sqlparse/engine/grouping.py repeatedly rescans comment-only statements before the MAX_GROUPING_TOKENS guard, causing quadratic CPU consumption through sqlparse.parse() and sqlparse.format(sql, strip_comments=True). This issue is fixed in version 0.6.0.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Package advisory (CVE-2026-71491)\n\nAffected packages:\n\n- `sqlparse <= 0.5.5`\n\nPatched in:\n\n- `sqlparse 0.6.0`\n\nSource: https://github.com/advisories/GHSA-f2ff-p2ww-7p4p\n\n## Vendor advisories\n\n- **RHSA-2026:61783** · Red Hat · fixed in: Red Hat Discovery 2 · released 2026-08-31 · [advisory](https://access.redhat.com/errata/RHSA-2026:61783)\n- **Red Hat VEX** · Important · affected: Red Hat Ansible Automation Platform 2, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift Container Platform 4, Red Hat OpenStack Platform 16.2, Red Hat OpenStack Platform 17.1, Red Hat OpenStack Platform 18.0, … · no fix planned: Red Hat Ansible Automation Platform 2, Red Hat OpenStack Platform 18.0, Red Hat Update Infrastructure 4 for Cloud Providers, Red Hat OpenShift AI (RHOAI), … · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-71491.json)\n- **RHSA-2026:67279** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.7 · released 2026-09-14 · [advisory](https://access.redhat.com/errata/RHSA-2026:67279)\n- **RHSA-2026:69289** · Red Hat · fixed in: Red Hat Discovery 2 · released 2026-09-21 · [advisory](https://access.redhat.com/errata/RHSA-2026:69289)","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[{"seq":5461,"id":"CVE-2026-71491","ts":1788887284621,"field":"cvss","old":null,"new":"7.5"},{"seq":4344,"id":"CVE-2026-71491","ts":1788886398518,"field":"cvss","old":"7.5","new":null},{"seq":3257,"id":"CVE-2026-71491","ts":1788883138450,"field":"cvss","old":null,"new":"7.5"}]}