Bug 2517527 (CVE-2026-54284)

Summary: CVE-2026-54284 sqlparse: sqlparse: Denial of Service via quadratic CPU consumption in SQL parsing
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedCC: akhatavk, anthomas, aos-team-art-private, asdas, brasmith, cmyers, cochase, dnakabaa, dpaolell, dranck, dschmidt, eglynn, ehelms, ggainey, jdelft, jjoyce, jlanda, jmitchel, jpasqual, jpretori, jschluet, jupierce, juwatts, jwong, kaycoth, kshier, lbrazdil, lcouzens, lgarciaa, lhh, mbiarnes, mburns, mdellweg, mgarciac, mhulan, mminar, nmoumoul, omaciel, osousa, pcreech, ppalepu, ppostler, prdhamdh, rbiba, rchan, sghai, sidsharm, simaishi, smallamp, sskracic, stcannon, suppawar, teagle, tmalecek, tpfromme, ttakamiy, vlaad, yguenane
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in sqlparse, a Python module for parsing SQL. A remote attacker could exploit a vulnerability in the TokenList construction and string conversion processes, specifically when handling nested token subtrees. This flaw leads to quadratic CPU consumption, which can result in a Denial of Service (DoS) by exhausting system resources before internal limits are reached.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description OSIDB Bzimport 2026-08-17 18:02:58 UTC
sqlparse is a non-validating SQL parser module for Python. Prior to 0.6.0, TokenList construction and string conversion in sqlparse/sql.py repeatedly flatten nested token subtrees constructed by group_parenthesis and group_case, causing quadratic CPU consumption through sqlparse.parse(), sqlparse.format(), and sqlparse.split() before depth and token limits terminate processing. This issue is fixed in version 0.6.0.

Comment 1 Jon Orris 2026-09-23 20:42:47 UTC
This issue has been addressed in the following products:

  Red Hat Ansible Automation Platform 2.7 for RHEL 10
  Red Hat Ansible Automation Platform 2.7 for RHEL 9

Via RHSA-2026:71112 https://access.redhat.com/errata/RHSA-2026:71112

Comment 2 Jon Orris 2026-09-23 20:50:41 UTC
This issue has been addressed in the following products:

  Red Hat Ansible Automation Platform 2.6 for RHEL 10
  Red Hat Ansible Automation Platform 2.6 for RHEL 9

Via RHSA-2026:71113 https://access.redhat.com/errata/RHSA-2026:71113

Comment 3 Jon Orris 2026-09-23 21:07:30 UTC
This issue has been addressed in the following products:

  Red Hat Ansible Automation Platform 2.5 for RHEL 9
  Red Hat Ansible Automation Platform 2.5 for RHEL 8

Via RHSA-2026:71114 https://access.redhat.com/errata/RHSA-2026:71114

Comment 4 Jon Orris 2026-10-01 22:12:19 UTC
This issue has been addressed in the following products:

  Red Hat Satellite 6.18 for RHEL 9

Via RHSA-2026:74504 https://access.redhat.com/errata/RHSA-2026:74504

Comment 5 Jon Orris 2026-10-01 22:13:16 UTC
This issue has been addressed in the following products:

  Red Hat Satellite 6.17 for RHEL 9

Via RHSA-2026:74505 https://access.redhat.com/errata/RHSA-2026:74505

Comment 6 Jon Orris 2026-10-01 22:32:33 UTC
This issue has been addressed in the following products:

  Red Hat Satellite 6.16 for RHEL 8
  Red Hat Satellite 6.16 for RHEL 9

Via RHSA-2026:74506 https://access.redhat.com/errata/RHSA-2026:74506