PT-2026-42043 · Sqlfluff · Sqlfluff

CVE-2026-46374

·

Published

2026-05-19

·

Updated

2026-06-12

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions SQLFluff versions prior to 4.2.0
Description In deployments where untrusted users can provide SQL queries to be linted, a malicious actor can submit an excessively long query to any application using the parser. This action triggers a Denial of Service (DoS), a state where a system becomes unavailable to its intended users, through resource exhaustion.
Recommendations Update to version 4.2.0 or later to utilize the configurable parse node limit, which is enabled by default to prevent this issue.

Exploit

Fix

DoS

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-46374
GHSA-73JC-5MRQ-PRW7
PYSEC-2026-210

Affected Products

Sqlfluff