VYPR

rpm package

opensuse/python-sqlparse&distro=openSUSE Leap 16.0

pkg:rpm/opensuse/python-sqlparse&distro=openSUSE%20Leap%2016.0

Vulnerabilities (5)

  • CVE-2026-84305MedSep 1, 2026
    affected < 0.5.3-160000.5.1fixed 0.5.3-160000.5.1

    sqlparse is a non-validating SQL parser module for Python. Prior to 0.6.0, sqlparse.format(sql, reindent=True) and sqlformat --reindent route attacker-controlled parenthesized tuple lists through ReindentFilter._get_offset() in sqlparse/filters/reindent.py, where _flatten_up_to_t

  • CVE-2026-71491HigAug 17, 2026
    affected < 0.5.3-160000.4.1fixed 0.5.3-160000.4.1

    sqlparse is a non-validating SQL parser module for Python. Prior to 0.6.0, group_comments in sqlparse/engine/grouping.py repeatedly rescans comment-only statements before the MAX_GROUPING_TOKENS guard, causing quadratic CPU consumption through sqlparse.parse() and sqlparse.format

  • CVE-2026-59894MedAug 17, 2026
    affected < 0.5.3-160000.4.1fixed 0.5.3-160000.4.1

    sqlparse is a non-validating SQL parser module for Python. Prior to 0.6.0, sqlparse/filters/output.py fails to escape existing backslashes before quotes in sqlparse.format output_format='python' and output_format='php' and the corresponding sqlformat -l modes, allowing crafted SQ

  • CVE-2026-59893HigAug 17, 2026
    affected < 0.5.3-160000.4.1fixed 0.5.3-160000.4.1

    sqlparse is a non-validating SQL parser module for Python. Prior to 0.6.0, SQL_REGEX in sqlparse/keywords.py and the per-position loop in sqlparse/lexer.py repeatedly scan unmatched dollar-quoted literal and multiline-comment delimiters, causing quadratic CPU consumption through

  • CVE-2026-54284HigAug 17, 2026
    affected < 0.5.3-160000.4.1fixed 0.5.3-160000.4.1

    sqlparse is a non-validating SQL parser module for Python. Prior to 0.6.0, TokenList construction and string conversion in sqlparse/sql.py repeatedly flatten nested token subtrees constructed by group_parenthesis and group_case, causing quadratic CPU consumption through sqlparse.