PT-2026-42042 · Sqlfluff · Sqlfluff
CVE-2026-46373
·
Published
2026-05-19
·
Updated
2026-06-11
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
SQLFluff versions prior to 4.1.0
Description
In deployments where untrusted users can provide SQL queries to be linted, a malicious user can submit a query with excessive nesting. This triggers a Denial of Service through resource exhaustion in any application utilizing the parser.
Recommendations
Update to version 4.1.0 or later to enable the configurable recursion limit that prevents this exploit.
Exploit
Fix
DoS
Uncontrolled Recursion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sqlfluff