Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-54284 is a high-severity vulnerability in the Python sqlparse module prior to version 0.6.0. The issue arises from inefficient algorithmic complexity during TokenList construction and string conversion, causing quadratic CPU consumption when using sqlparse.parse(), sqlparse.format(), and sqlparse.split(). This inefficiency is due to repeatedly flattening nested token subtrees. The vulnerability is fixed in sqlparse version 0.6.0. Join the discussion | CVE Database V5 | 08/19/2026, 00:00:00 UTC Added: 08/17/2026, 17:59:08 UTC |
CVE-2026-71491 is a high-severity vulnerability in the Python sqlparse module prior to version 0.6.0. The issue involves uncontrolled resource consumption due to the group_comments function repeatedly rescanning comment-only SQL statements, leading to quadratic CPU usage during parsing and formatting operations. This vulnerability can cause significant performance degradation when processing certain SQL inputs. The issue is fixed in sqlparse version 0.6.0. Join the discussion | CVE Database V5 | 08/17/2026, 18:18:00 UTC Added: 08/17/2026, 17:41:43 UTC |
0 CVE-2026-59893 is a high-severity vulnerability in the Python sqlparse module prior to version 0.6.0. The issue involves inefficient regular expression complexity causing quadratic CPU consumption when parsing certain SQL constructs such as unmatched dollar-quoted literals and multiline comments. This can lead to denial of service through excessive CPU usage. The vulnerability is fixed in sqlparse version 0.6.0. Join the discussion | CVE Database V5 | 08/17/2026, 18:17:00 UTC Added: 08/17/2026, 17:59:08 UTC |
0 sqlparse is a non-validating SQL parser module for Python. Prior to 0.6.0, sqlparse/filters/output.py fails to escape existing backslashes before quotes in sqlparse.format output_format='python' and output_format='php' and the corresponding sqlformat -l modes, allowing crafted SQL to terminate the generated string and inject Python or PHP code when a downstream consumer executes or imports the generated source. This issue is fixed in version 0.6.0. Join the discussion | CVE Database V5 | 08/17/2026, 17:14:22 UTC Added: 08/17/2026, 17:27:20 UTC |
0 Passing a heavily nested list to sqlparse.parse() leads to a Denial of Service due to RecursionError. Join the discussion | CVE Database V5 | 04/30/2024, 14:23:03 UTC Added: 11/03/2025, 22:16:09 UTC |
0 sqlparse is a non-validating SQL parser module for Python. In affected versions the SQL parser contains a regular expression that is vulnerable to ReDoS (Regular Expression Denial of Service). This issue was introduced by commit `e75e358`. The vulnerability may lead to Denial of Service (DoS). This issues has been fixed in sqlparse 0.4.4 by commit `c457abd5f`. Users are advised to upgrade. There are no known workarounds for this issue. Join the discussion | CVE Database V5 | 04/18/2023, 21:32:11 UTC Added: 11/03/2025, 22:01:19 UTC |
Showing 1 to 6 of 6 results