---
id: CVE-2026-59893
title: sqlparse is a non-validating SQL parser module for Python
summary: >-
  sqlparse is a non-validating SQL parser module for Python. Prior to 0.6.0,
  SQL_REGEX in sqlparse/keywords.py and the per-position loop in
  sqlparse/lexer.py repeatedly scan unmatched dollar-quoted literal and
  multiline-comment delimiters,…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-1333
vendor: sqlparse
product: sqlparse
affected:
  - sqlparse < 0.6.0
patched:
  - sqlparse 0.6.0
published: '2026-08-17'
updated: '2026-09-18'
sourceUpdated: '2026-09-18T20:09:01.757'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-59893'
references:
  - url: >-
      https://github.com/andialbrecht/sqlparse/commit/d1d80602741f77ec78e5a04ce4719244cf32352e
    label: security-advisories@github.com
  - url: >-
      https://github.com/andialbrecht/sqlparse/security/advisories/GHSA-prg7-hcfm-mfcr
    label: security-advisories@github.com
  - url: >-
      https://github.com/andialbrecht/sqlparse/security/advisories/GHSA-prg7-hcfm-mfcr
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
  - url: 'https://github.com/andialbrecht/sqlparse'
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-59893.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-59893'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2517523'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-59893'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-59893'
  - url: 'https://access.redhat.com/errata/RHSA-2026:61783'
  - url: 'https://github.com/advisories/GHSA-prg7-hcfm-mfcr'
  - url: 'https://access.redhat.com/errata/RHSA-2026:67279'
  - url: 'https://access.redhat.com/errata/RHSA-2026:69539'
  - url: 'https://access.redhat.com/errata/RHSA-2026:71113'
  - url: 'https://access.redhat.com/errata/RHSA-2026:71112'
  - url: 'https://access.redhat.com/errata/RHSA-2026:71114'
  - url: 'https://access.redhat.com/errata/RHSA-2026:71210'
  - url: 'https://access.redhat.com/errata/RHSA-2026:71179'
  - url: 'https://access.redhat.com/errata/RHSA-2026:71177'
tags:
  - nvd
  - osv
  - pip
  - csaf
  - vex
  - red-hat
  - ghsa
epss: 0.00337
epssPercentile: 0.24409
aliases:
  - GHSA-prg7-hcfm-mfcr
  - PYSEC-2026-3698
ecosystem: pip
ingestedAt: '2026-08-17T17:58:10.140Z'
---

## Overview

sqlparse is a non-validating SQL parser module for Python. Prior to 0.6.0, SQL_REGEX in sqlparse/keywords.py and the per-position loop in sqlparse/lexer.py repeatedly scan unmatched dollar-quoted literal and multiline-comment delimiters, causing quadratic CPU consumption through sqlparse.parse(), sqlparse.format(), and sqlparse.split(). This issue is fixed in version 0.6.0.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Package advisory (CVE-2026-59893)

Affected packages:

- `sqlparse < 0.6.0`

Patched in:

- `sqlparse 0.6.0`

Source: https://osv.dev/vulnerability/GHSA-prg7-hcfm-mfcr

## Vendor advisories

- **RHSA-2026:61783** · Red Hat · fixed in: Red Hat Discovery 2 · released 2026-08-31 · [advisory](https://access.redhat.com/errata/RHSA-2026:61783)
- **Red Hat VEX** · Important · affected: Red Hat Ansible Automation Platform 2, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift Container Platform 4, Red Hat OpenStack Platform 16.2, Red Hat OpenStack Platform 17.1, Red Hat OpenStack Platform 18.0, … · no fix planned: Red Hat Update Infrastructure 4 for Cloud Providers, Red Hat Ansible Automation Platform 2, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift Container Platform 4, … · updated 2026-09-24 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-59893.json)
- **RHSA-2026:67279** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.7 · released 2026-09-14 · [advisory](https://access.redhat.com/errata/RHSA-2026:67279)
- **RHSA-2026:69539** · Red Hat · fixed in: Red Hat OpenShift AI 3.5 · released 2026-09-21 · [advisory](https://access.redhat.com/errata/RHSA-2026:69539)
- **RHSA-2026:71113** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.6 for RHEL 10, Red Hat Ansible Automation Platform 2.6 for RHEL 9 · released 2026-09-23 · [advisory](https://access.redhat.com/errata/RHSA-2026:71113)
- **RHSA-2026:71112** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.7 for RHEL 10, Red Hat Ansible Automation Platform 2.7 for RHEL 9 · released 2026-09-23 · [advisory](https://access.redhat.com/errata/RHSA-2026:71112)
- **RHSA-2026:71114** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.5 for RHEL 8, Red Hat Ansible Automation Platform 2.5 for RHEL 9 · released 2026-09-23 · [advisory](https://access.redhat.com/errata/RHSA-2026:71114)
- **RHSA-2026:71210** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.5 · released 2026-09-23 · [advisory](https://access.redhat.com/errata/RHSA-2026:71210)
- **RHSA-2026:71179** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.6 · released 2026-09-23 · [advisory](https://access.redhat.com/errata/RHSA-2026:71179)
- **RHSA-2026:71177** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.7 · released 2026-09-23 · [advisory](https://access.redhat.com/errata/RHSA-2026:71177)
