sqlparse is vulnerable to Allocation of Resources Without Limits or Throttling
20
Low Risk
Affected versions of this package are vulnerable to a Denial of Service (DoS) due to insufficient parsing limits for large lists of tuples in SQL statements, allowing an attacker to craft a malicious, overly complex SQL statement with deeply nested tuples to cause excessive CPU consumption and service unavailability, which is mitigated by the introduction of configurable limits on grouping depth and tokens (MAX_GROUPING_DEPTH=100, MAX_GROUPING_TOKENS=10000).
You are affected if you are using a version that falls within the vulnerable range.
sqlparse is vulnerable to Allocation of Resources Without Limits or Throttling in versions 0.1.0 - 0.5.3.
Upgrade the sqlparse library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant