Sqlfluff is a focused SQL linting and formatting tool whose vulnerability surface centers on input-processing and resource-handling issues such as injection vulnerabilities, uncontrolled recursion, and resource exhaustion. The durable signal reflects the parser-intensive nature of the tool and its role in processing untrusted or malformed SQL statements. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Sqlfluff over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-46374HIGH SQLFluff is a modular SQL linter and auto-formatter with support for multiple dialects and templated code. Prior to version 4.2.0, in deployments where untrusted users can provide | Jun 9, 2026 | 7.5 | 33 | NO | NO |
CVE-2026-46373HIGH SQLFluff is a modular SQL linter and auto-formatter with support for multiple dialects and templated code. Prior to version 4.1.0, in deployments where untrusted users can provide | Jun 9, 2026 | 7.5 | 32 | NO | NO |
CVE-2023-36830HIGH SQLFluff is a SQL linter. Prior to version 2.1.2, in environments where untrusted users have access to the config files, there is a potential security vulnerability where those use | Jul 6, 2023 | 7.8 | 22 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Sqlfluff.
Media articles that mention a CVE ID that affects a product developed by Sqlfluff — matched by CVE ID, not by vendor name.