VulnSea

sqlparse vulnerabilities

CVEs whose affected-version data names the sqlparse package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

7 CVEsRSS

CVE-2026-84305Medium
3w ago

sqlparse is a non-validating SQL parser module for Python

sqlparse is a non-validating SQL parser module for Python. Prior to 0.6.0, sqlparse.format(sql, reindent=True) and sqlformat --reindent route attacker-controlled parenthesized tuple lists through ReindentFilter._get_offset() in sqlparse/…

Sunlitsqlparse · sqlparseEPSS 0.13%via NVD
CVE-2026-59894Medium
1mo ago

sqlparse is a non-validating SQL parser module for Python

sqlparse is a non-validating SQL parser module for Python. Prior to 0.6.0, sqlparse/filters/output.py fails to escape existing backslashes before quotes in sqlparse.format output_format='python' and output_format='php' and the correspond…

Sunlitsqlparse · sqlparseEPSS 0.13%via NVD
CVE-2026-54284High· 7.5
1mo ago

sqlparse is a non-validating SQL parser module for Python

sqlparse is a non-validating SQL parser module for Python. Prior to 0.6.0, TokenList construction and string conversion in sqlparse/sql.py repeatedly flatten nested token subtrees constructed by group_parenthesis and group_case, causing …

Twilightsqlparse · sqlparseEPSS 0.26%via NVD
CVE-2026-59893High· 7.5
1mo ago

sqlparse is a non-validating SQL parser module for Python

sqlparse is a non-validating SQL parser module for Python. Prior to 0.6.0, SQL_REGEX in sqlparse/keywords.py and the per-position loop in sqlparse/lexer.py repeatedly scan unmatched dollar-quoted literal and multiline-comment delimiters,…

Twilightsqlparse · sqlparseEPSS 0.28%via NVD
GHSA-27jp-wm6q-gp25Medium
7mo ago

sqlparse: formatting list of tuples leads to denial of service

sqlparse: formatting list of tuples leads to denial of service

Sunlitsqlparse · sqlparsevia OSV
CVE-2024-4340High· 7.5
2y ago

sqlparse parsing heavily nested list leads to Denial of Service

sqlparse parsing heavily nested list leads to Denial of Service

Twilightsqlparse · sqlparseEPSS 3.2%via OSV
CVE-2021-32839High· 7.5
5y ago

StripComments filter contains a regular expression that is vulnerable to ReDOS (Regular Expression Denial of Service)

StripComments filter contains a regular expression that is vulnerable to ReDOS (Regular Expression Denial of Service)

Twilightsqlparse · sqlparseEPSS 2.3%via OSV
sqlparse vulnerabilities (CVEs) · VulnSea