PT-2026-42043 · Sqlfluff · Sqlfluff
CVE-2026-46374
·
Published
2026-05-19
·
Updated
2026-06-12
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
SQLFluff versions prior to 4.2.0
Description
In deployments where untrusted users can provide SQL queries to be linted, a malicious actor can submit an excessively long query to any application using the parser. This action triggers a Denial of Service (DoS), a state where a system becomes unavailable to its intended users, through resource exhaustion.
Recommendations
Update to version 4.2.0 or later to utilize the configurable parse node limit, which is enabled by default to prevent this issue.
Exploit
Fix
DoS
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sqlfluff