Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-cfqr-cjx5-5jcm | sqlparse: Reindentation of tuple lists causes near-cap quadratic CPU consumption |
Wed, 02 Sep 2026 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Andialbrecht
Andialbrecht sqlparse |
|
| Vendors & Products |
Andialbrecht
Andialbrecht sqlparse |
Tue, 01 Sep 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | sqlparse is a non-validating SQL parser module for Python. Prior to 0.6.0, sqlparse.format(sql, reindent=True) and sqlformat --reindent route attacker-controlled parenthesized tuple lists through ReindentFilter._get_offset() in sqlparse/filters/reindent.py, where _flatten_up_to_token() repeatedly rebuilds and joins the statement prefix. Thousands of offset calculations walk an expanding token tree, producing quadratic CPU consumption for inputs that remain below MAX_GROUPING_TOKENS and causing request delays, reduced throughput, or worker starvation. This issue is fixed in version 0.6.0. | |
| Title | sqlparse: Reindentation of tuple lists causes near-cap quadratic CPU consumption | |
| Weaknesses | CWE-407 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-09-01T19:12:52.039Z
Reserved: 2026-09-01T16:17:43.078Z
Link: CVE-2026-84305
No data.
Status : Received
Published: 2026-09-01T19:17:30.887
Modified: 2026-09-01T20:17:24.610
Link: CVE-2026-84305
No data.
OpenCVE Enrichment
Updated: 2026-09-02T03:15:04Z
Github GHSA