highVulnerability

CVE-2026-71491

### Summary A comment-only statement (`-- c\n`*n) may cause a Denial of Service (DoS). ### Details Location: [sqlparse/engine/grouping.py:331-341](https://github.com/andialbrecht/sqlparse/blob/f80af6a4007f11ada847218df8c29dc859238290/sqlparse/engine/grouping.py#L332) (`group_comments`), invoked first in `group()` at `grouping.py:439`. Reachable via `sqlparse.parse()` and `sqlparse.format(sql, strip_comments=True)`. A statement made of many single-line comments (`'-- c\n'` repeated) lexes in O(n) but `group_comments` is O(n²): ```python def group_comments(tlist): tidx, token = tlist.token_next_by(t=T.Comment) while token: eidx, end = tlist.token_not_matching( lambda tk: imt(tk, t=T.Comment) or tk.is_newline, idx=tidx) ... tidx, token = tlist.token_next_by(t=T.Comment, idx=tidx) ``` The `while` loop runs n times and each `token_next_by` / `token_not_matching` rescans the O(n) remaining tokens. When all tokens are comments/newlines nothing ever groups, yet the full scan is repeated per token. Two following factors increase the severity: 1. `group_comments` runs first in `group()` (`grouping.py:439`), before the `_group_matching` token-count guard (`grouping.py:34-39`). So the entire quadratic cost is paid even on oversized input. `MAX_GROUPING_TOKENS` does not provide protection on this vector. 2. It sits on the primary sanitizer path: `format(sql, strip_comments=True)`, used by query loggers, SQL firewalls, ORMs, and migration tools. ### PoC Tested using Python 3.14: ```python import time, sqlparse for n in (1000, 2000, 4000): s = "-- c\n" * n t = time.perf_counter() sqlparse.format(s, strip_comments=True) print(f"n={n:5d} format(strip_comments)={1000*(time.perf_counter()-t):7.1f} ms") ``` Output: ``` n= 1000 format(strip_comments)= 106.0 ms n= 2000 format(strip_comments)= 403.3 ms n= 4000 format(strip_comments)= 1602.8 ms ``` Time increase of ~4× per 2× input (quadratic). `parse()` shows the

Properties

ghsa_id
GHSA-f2ff-p2ww-7p4p
severity
high
summary
sqlparse: Quadratic O(n²) DoS in group_comments
epss_score
0.00263
cve_id
CVE-2026-71491
is_ghsa_only
false
ghsa_published
2026-08-17T17:21:00Z
source_url
https://github.com/advisories/GHSA-f2ff-p2ww-7p4p
epss_percentile
0.18201
ghsa_updated
2026-08-17T17:21:02Z

Related Entities (6)

ENRICHED_BY (1)

[Source]FIRST EPSS

VULNERABLE_TO (1)

[Software]pip/sqlparse

AFFECTS (1)

[Software]pip/sqlparse

HAS_WEAKNESS (2)

[Weakness]Uncontrolled Resource Consumption
[Weakness]Inefficient Algorithmic Complexity

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph