PT-2026-42042 · Sqlfluff · Sqlfluff

CVE-2026-46373

·

Published

2026-05-19

·

Updated

2026-06-11

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions SQLFluff versions prior to 4.1.0
Description In deployments where untrusted users can provide SQL queries to be linted, a malicious user can submit a query with excessive nesting. This triggers a Denial of Service through resource exhaustion in any application utilizing the parser.
Recommendations Update to version 4.1.0 or later to enable the configurable recursion limit that prevents this exploit.

Exploit

Fix

DoS

Uncontrolled Recursion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-46373
GHSA-WMHF-FQC8-VXHH
PYSEC-2026-209

Affected Products

Sqlfluff