Sploitus

CVE-2026-54284

1 known exploit for CVE-2026-54284

sqlparse is a non-validating SQL parser module for Python. Prior to 0.6.0, TokenList construction and string conversion in sqlparse/sql.py repeatedly flatten nested token subtrees constructed by group_parenthesis and group_case, causing quadratic CPU consumption through sqlparse.parse(), sqlparse.format(), and sqlparse.split() before depth and token limits terminate processing. This issue is fixed in version 0.6.0.

Affected products
Sqlparse
CVSS 4.0
8.7 HIGH
Weakness
CWE-1333, CWE-407
NVD status
Received
Published
2026-08-17
CVE-2026-54284 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2026-54284

Proof-of-concept code and exploit modules indexed by Sploitus