sqlparse, Denial of Service (DoS), CVE-2026-71491 (High) -DC-Aug2026-1548

Listen to this Post

Technical

CVE-2026-71491 is a quadratic complexity Denial of Service (DoS) vulnerability in the Python SQL parsing library sqlparse, affecting all versions prior to 0.6.0. The flaw resides in the `group_comments` function within `sqlparse/engine/grouping.py` at lines 331–341. This function is invoked first during the `group()` process (grouping.py:439), before any token-count guards are applied. It is reachable via both `sqlparse.parse()` and sqlparse.format(sql, strip_comments=True).
The vulnerability is triggered by a crafted input consisting of many repeated single-line SQL comments, such as "-- c\n" n. While the lexer processes these tokens in linear O(n) time, the `group_comments` function exhibits O(n²) behavior. The `while` loop iterates over every comment token, and within each iteration, the helper functions `token_next_by` and `token_not_matching` rescan the entire remaining list of O(n) tokens. When the entire input consists solely of comments and newlines, no grouping actually occurs, yet the full quadratic scan is repeated for every single token.

Two factors significantly increase the severity:

1. `group_comments` runs before the `_group_matching` token-count guard (MAX_GROUPING_TOKENS), meaning the quadratic cost is fully paid even on oversized input.
2. The vulnerable path sits on the primary sanitizer path — `format(sql, strip_comments=True)` — which is widely used by query loggers, SQL firewalls, ORMs, and migration tools.
A Proof of Concept demonstrates the quadratic scaling: for n=1000 comments, execution takes ~106 ms; for n=2000, ~403 ms; and for n=4000, ~1602 ms — a ~4× increase for every 2× increase in input size. Instrumented scan counts confirm exactly 1.0M, 4.0M, and 16.0M token rescans for n=1000, 2000, and 4000 respectively. A ~250 KB comment-only payload can force minutes of CPU consumption, bypassing the 10,000 token cap.

DailyCVE Form:

Platform: Python sqlparse
Version: < 0.6.0
Vulnerability: O(n²) DoS
Severity: High (CVSS 8.7)
date: 2026-08-17

Prediction: 2026-08-17

What Undercode Say:

Analytics of the vulnerability show that the `group_comments` function is the primary bottleneck. The while loop and its nested rescans are the root cause. The following command can be used to test a system for this vulnerability:

python3 -c "import time, sqlparse; s = '-- c\n' 4000; t = time.perf_counter(); sqlparse.format(s, strip_comments=True); print(f'{1000(time.perf_counter()-t):.1f} ms')"

To reproduce the full PoC from the advisory:

import time
import sqlparse
for n in (1000, 2000, 4000):
s = "-- c\n" n
t = time.perf_counter()
sqlparse.format(s, strip_comments=True)
print(f"n={n:5d} format(strip_comments)={1000(time.perf_counter()-t):7.1f} ms")

Expected output:

n= 1000 format(strip_comments)= 106.0 ms
n= 2000 format(strip_comments)= 403.3 ms
n= 4000 format(strip_comments)= 1602.8 ms

Exploit: (Educational Purposes!)

To exploit this vulnerability, an attacker can craft a malicious SQL payload consisting of thousands of single-line comments and submit it to any application that parses or formats SQL using `sqlparse` with strip_comments=True. For example:

-- c
-- c
-- c
... (repeated thousands of times)

Submitting this payload to a vulnerable endpoint (e.g., a query logger, SQL firewall, or ORM that sanitizes comments) will cause excessive CPU consumption, leading to a denial of service.

Protection:

  • Upgrade to `sqlparse` version 0.6.0 or later, where this issue is fixed.
  • As a temporary workaround, avoid using `sqlparse.format()` with `strip_comments=True` until the upgrade is applied.
  • Implement rate limiting and input size restrictions on SQL queries processed by the application to mitigate large malicious payloads.
  • Deploy Web Application Firewalls (WAF) or input validation to block requests containing an abnormally high number of SQL comment lines.

Impact:

Successful exploitation of this vulnerability allows an unauthenticated remote attacker to cause a Denial of Service (DoS) by exhausting CPU resources. A single 250 KB comment-only payload can consume minutes of CPU time per request. This is particularly dangerous because the vulnerable code path is commonly used in critical security and logging components, such as query sanitizers, SQL firewalls, ORMs, and database migration tools. The CVSS v4.0 base score is 8.7 (High).

🎯Let’s Practice Exploiting & Learn Patching For Free:

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top