Sqlparse is a lightweight Python SQL parser library with focused deployment across tools and applications that process SQL statements programmatically. Its vulnerability surface concentrates in parser-oriented weakness classes—inefficient regular expression complexity and uncontrolled resource consumption—that arise from the complexity of SQL dialect handling and input validation at the lexical and syntactic layers. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Sqlparse Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-32839HIGH sqlparse is a non-validating SQL parser module for Python. In sqlparse versions 0.4.0 and 0.4.1 there is a regular Expression Denial of Service in sqlparse vulnerability. The regul | Sep 20, 2021 | 7.5 | 25 | NO | NO |
CVE-2023-30608HIGH sqlparse is a non-validating SQL parser module for Python. In affected versions the SQL parser contains a regular expression that is vulnerable to ReDoS (Regular Expression Denial | Apr 18, 2023 | 7.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Sqlparse Project.
Media articles that mention a CVE ID that affects a product developed by Sqlparse Project — matched by CVE ID, not by vendor name.