Security: andialbrecht/sqlparse
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
Reindentation of tuple lists causes near-cap quadratic CPU consumptionGHSA-cfqr-cjx5-5jcm published
Aug 13, 2026 by andialbrechtModerate -
Generated Python and PHP snippets allow SQL string breakout through unescaped backslashesGHSA-3496-9g83-7v6x published
Aug 10, 2026 by andialbrechtModerate -
Quadratic O(n²) DoS in group_commentsGHSA-f2ff-p2ww-7p4p published
Aug 10, 2026 by andialbrechtModerate -
Inefficient Regex Handling of Dollar-Quoted SQL Literals Leads to ReDoS (Denial of Service)GHSA-prg7-hcfm-mfcr published
Aug 13, 2026 by andialbrechtHigh -
TokenList.__init__ materializes O(subtree) value per group, causing CPU DoS before depth/token caps triggerGHSA-pwgv-4x5q-6m9f published
Aug 13, 2026 by andialbrechtHigh -
Formatting list of tuples leads to denial of serviceGHSA-27jp-wm6q-gp25 published
Nov 25, 2025 by andialbrechtLow -
Parsing heavily nested list leads to Denial of ServiceGHSA-2m57-hf25-phgg published
Apr 13, 2024 by andialbrechtHigh -
Parser contains a regular expression that is vulnerable to ReDOS (Regular Expression Denial of Service)GHSA-rrm6-wvj7-cwh2 published
Apr 18, 2023 by andialbrechtModerate -
StripComments filter contains a regular expression that is vulnerable to ReDOS (Regular Expression Denial of Service)GHSA-p5w8-wqhj-9hhf published
Sep 10, 2021 by andialbrechtCritical