---
id: CVE-2026-71491
title: sqlparse is a non-validating SQL parser module for Python
summary: >-
  sqlparse is a non-validating SQL parser module for Python. Prior to 0.6.0,
  group_comments in sqlparse/engine/grouping.py repeatedly rescans comment-only
  statements before the MAX_GROUPING_TOKENS guard, causing quadratic CPU
  consumption t…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-400
  - CWE-407
  - CWE-1050
vendor: Red Hat
product: Red Hat OpenStack Platform 16.2
affected:
  - ansible_automation_platform 2
  - openshift_ai_rhoai
  - openshift_container_platform 4
  - openstack_platform 16.2
  - openstack_platform 17.1
  - openstack_platform 18.0
  - satellite 6
  - update_infrastructure_4_for_cloud_providers
  - update_infrastructure 5
  - self_service_automation_portal 2
  - discovery 2
patched:
  - discovery 2
published: '2026-08-17'
updated: '2026-09-09'
sourceUpdated: '2026-09-09T21:11:46.833'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-71491'
references:
  - url: >-
      https://github.com/andialbrecht/sqlparse/commit/ef2012a5eeb491e604dea2b00d516904a3830c87
    label: security-advisories@github.com
  - url: >-
      https://github.com/andialbrecht/sqlparse/security/advisories/GHSA-f2ff-p2ww-7p4p
    label: security-advisories@github.com
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-71491.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-71491'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2517518'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-71491'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-71491'
  - url: 'https://access.redhat.com/errata/RHSA-2026:61783'
  - url: 'https://github.com/advisories/GHSA-f2ff-p2ww-7p4p'
  - url: 'https://github.com/andialbrecht/sqlparse'
  - url: 'https://access.redhat.com/errata/RHSA-2026:67279'
  - url: 'https://access.redhat.com/errata/RHSA-2026:69289'
  - url: 'https://access.redhat.com/errata/RHSA-2026:69539'
  - url: 'https://access.redhat.com/errata/RHSA-2026:71113'
  - url: 'https://access.redhat.com/errata/RHSA-2026:71112'
  - url: 'https://access.redhat.com/errata/RHSA-2026:71114'
  - url: 'https://access.redhat.com/errata/RHSA-2026:71210'
  - url: 'https://access.redhat.com/errata/RHSA-2026:71179'
  - url: 'https://access.redhat.com/errata/RHSA-2026:71177'
tags:
  - nvd
  - csaf
  - vex
  - red-hat
  - ghsa
  - pip
  - osv
epss: 0.00263
epssPercentile: 0.18433
aliases:
  - GHSA-f2ff-p2ww-7p4p
  - PYSEC-2026-3697
ecosystem: pip
cvssSource: vendor
ingestedAt: '2026-08-17T17:58:10.919Z'
---

## Overview

sqlparse is a non-validating SQL parser module for Python. Prior to 0.6.0, group_comments in sqlparse/engine/grouping.py repeatedly rescans comment-only statements before the MAX_GROUPING_TOKENS guard, causing quadratic CPU consumption through sqlparse.parse() and sqlparse.format(sql, strip_comments=True). This issue is fixed in version 0.6.0.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Package advisory (CVE-2026-71491)

Affected packages:

- `sqlparse <= 0.5.5`

Patched in:

- `sqlparse 0.6.0`

Source: https://github.com/advisories/GHSA-f2ff-p2ww-7p4p

## Vendor advisories

- **RHSA-2026:61783** · Red Hat · fixed in: Red Hat Discovery 2 · released 2026-08-31 · [advisory](https://access.redhat.com/errata/RHSA-2026:61783)
- **Red Hat VEX** · Important · affected: Red Hat Ansible Automation Platform 2, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift Container Platform 4, Red Hat OpenStack Platform 16.2, Red Hat OpenStack Platform 17.1, Red Hat OpenStack Platform 18.0, … · no fix planned: Red Hat Ansible Automation Platform 2, Red Hat OpenStack Platform 18.0, Red Hat Update Infrastructure 4 for Cloud Providers, Red Hat OpenShift AI (RHOAI), … · updated 2026-09-24 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-71491.json)
- **RHSA-2026:67279** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.7 · released 2026-09-14 · [advisory](https://access.redhat.com/errata/RHSA-2026:67279)
- **RHSA-2026:69289** · Red Hat · fixed in: Red Hat Discovery 2 · released 2026-09-21 · [advisory](https://access.redhat.com/errata/RHSA-2026:69289)
- **RHSA-2026:69539** · Red Hat · fixed in: Red Hat OpenShift AI 3.5 · released 2026-09-21 · [advisory](https://access.redhat.com/errata/RHSA-2026:69539)
- **RHSA-2026:71113** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.6 for RHEL 10, Red Hat Ansible Automation Platform 2.6 for RHEL 9 · released 2026-09-23 · [advisory](https://access.redhat.com/errata/RHSA-2026:71113)
- **RHSA-2026:71112** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.7 for RHEL 10, Red Hat Ansible Automation Platform 2.7 for RHEL 9 · released 2026-09-23 · [advisory](https://access.redhat.com/errata/RHSA-2026:71112)
- **RHSA-2026:71114** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.5 for RHEL 8, Red Hat Ansible Automation Platform 2.5 for RHEL 9 · released 2026-09-23 · [advisory](https://access.redhat.com/errata/RHSA-2026:71114)
- **RHSA-2026:71210** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.5 · released 2026-09-23 · [advisory](https://access.redhat.com/errata/RHSA-2026:71210)
- **RHSA-2026:71179** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.6 · released 2026-09-23 · [advisory](https://access.redhat.com/errata/RHSA-2026:71179)
- **RHSA-2026:71177** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.7 · released 2026-09-23 · [advisory](https://access.redhat.com/errata/RHSA-2026:71177)
