Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:pypi/sqlparse

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-54284 is a high-severity vulnerability in the Python sqlparse module prior to version 0.6.0. The issue arises from inefficient algorithmic complexity during TokenList construction and string conversion, causing quadratic CPU consumption when using sqlparse.parse(), sqlparse.format(), and sqlparse.split(). This inefficiency is due to repeatedly flattening nested token subtrees. The vulnerability is fixed in sqlparse version 0.6.0.

Join the discussion

CVE-2026-71491 is a high-severity vulnerability in the Python sqlparse module prior to version 0.6.0. The issue involves uncontrolled resource consumption due to the group_comments function repeatedly rescanning comment-only SQL statements, leading to quadratic CPU usage during parsing and formatting operations. This vulnerability can cause significant performance degradation when processing certain SQL inputs. The issue is fixed in sqlparse version 0.6.0.

Join the discussion

CVE-2026-59893 is a high-severity vulnerability in the Python sqlparse module prior to version 0.6.0. The issue involves inefficient regular expression complexity causing quadratic CPU consumption when parsing certain SQL constructs such as unmatched dollar-quoted literals and multiline comments. This can lead to denial of service through excessive CPU usage. The vulnerability is fixed in sqlparse version 0.6.0.

Join the discussion

sqlparse is a non-validating SQL parser module for Python. Prior to 0.6.0, sqlparse/filters/output.py fails to escape existing backslashes before quotes in sqlparse.format output_format='python' and output_format='php' and the corresponding sqlformat -l modes, allowing crafted SQL to terminate the generated string and inject Python or PHP code when a downstream consumer executes or imports the generated source. This issue is fixed in version 0.6.0.

Join the discussion
0

Passing a heavily nested list to sqlparse.parse() leads to a Denial of Service due to RecursionError.

Join the discussion

sqlparse is a non-validating SQL parser module for Python. In affected versions the SQL parser contains a regular expression that is vulnerable to ReDoS (Regular Expression Denial of Service). This issue was introduced by commit `e75e358`. The vulnerability may lead to Denial of Service (DoS). This issues has been fixed in sqlparse 0.4.4 by commit `c457abd5f`. Users are advised to upgrade. There are no known workarounds for this issue.

Join the discussion

Showing 1 to 6 of 6 results

Filters:Package: pkg:pypi/sqlparse
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses