Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-f2ff-p2ww-7p4p | sqlparse: Quadratic O(n²) DoS in group_comments |
Mon, 17 Aug 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | sqlparse is a non-validating SQL parser module for Python. Prior to 0.6.0, group_comments in sqlparse/engine/grouping.py repeatedly rescans comment-only statements before the MAX_GROUPING_TOKENS guard, causing quadratic CPU consumption through sqlparse.parse() and sqlparse.format(sql, strip_comments=True). This issue is fixed in version 0.6.0. | |
| Title | sqlparse: Quadratic O(n²) DoS in group_comments | |
| Weaknesses | CWE-400 CWE-407 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-08-17T17:16:48.973Z
Reserved: 2026-08-06T19:56:23.725Z
Link: CVE-2026-71491
No data.
Status : Received
Published: 2026-08-17T18:18:12.120
Modified: 2026-08-17T18:18:12.120
Link: CVE-2026-71491
No data.
OpenCVE Enrichment
Updated: 2026-08-17T18:30:04Z
Github GHSA