sqlparse ReDoS, CVE-2024-12345 (Critical) -DC-Aug2026-1554

Listen to this Post

The vulnerability arises from a flawed regex in sqlparse/keywords.py:33, which uses a backreference `(\1)` to match closing dollar-quote delimiters in SQL literals. The regex `((?$tag$) into group 1, then lazily matches any characters `[\s\S]?` until it finds the same delimiter again. When no closing delimiter exists for a given opener, the regex engine backtracks and scans the entire remaining input before failing. The lexer applies this regex at every character position in the input string, as seen in sqlparse/lexer.py:136-138. For an input with N unique, unmatched dollar-quote openers, each opener triggers a full scan of the remaining text, resulting in O(N²) total work. The data flow from public API to the vulnerable sink is: parse() → parsestream() → FilterStack.run() → lexer.tokenize(), with no length limits or timeouts. The `MAX_GROUPING_TOKENS` limit in grouping.py fires only after lexing, offering no protection. Empirical scaling confirms super-linear growth; e.g., from n=1000 to n=2000, time increases by 3.31× for a 2× input increase. The same pattern class exists in multiline-comment regexes (/\\+[\s\S]?\/ and /\[\s\S]?\/), where unterminated `/` openers cause identical quadratic behavior due to the lexer loop retrying each pattern at every position.

DailyCVE Form:

Platform: sqlparse Python
Version: 0.5.6.dev0
Vulnerability: ReDoS
Severity: Critical
Date: 2026-08-18

Prediction: December 2024

What Undercode Say:

Analytics:

  • Timing ratios confirm O(n²): 3.31x for 2x input.
  • Attack vector: unique unmatched `$tag$` or `/x ` openers.
  • No authentication or privileges needed.
  • Affects all APIs: parse(), format(), split().
  • CVSS v3.1: 7.5 (High) – AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H.

Bash commands for reproduction:

Clone vulnerable commit
git clone https://github.com/andialbrecht/sqlparse.git
cd sqlparse && git checkout c923da9
Build Docker image
docker build -t sqlparse-vuln001 -f vuln-001/Dockerfile .
Run PoC with no network
docker run --rm --network=none sqlparse-vuln001

PoC code snippet:

import time, sqlparse
def make_payload(n):
return " ".join(f"$a{i}$x" for i in range(n))
for n in [250,500,1000,2000]:
t0=time.perf_counter(); sqlparse.parse(make_payload(n))
print(f"n={n} elapsed={time.perf_counter()-t0:.3f}s")

Exploit: (Educational Purposes!)

  • For dollar-quote: send `$a0$x $a1$x … $aN$x` to any endpoint that parses SQL.
  • For comments: send `/x ` repeated N times (padded to avoid immediate closure).
  • Observe CPU spike and linear-to-quadratic scaling in response latency.
  • Example HTTP POST: {"sql": "$a0$x $a1$x ..."}.

Protection:

  • Upgrade to patched version (>=0.5.1) with deterministic two-pass delimiter resolution.
  • Apply workaround: pre-filter input for `$[^$]$` or `/\` patterns and reject long sequences.
  • Set regex timeout using `timeout` parameter in Python’s `re` module (if backported).
  • Limit input length to < 1KB to reduce attack surface.

Impact:

  • Single crafted request can exhaust CPU cores, causing denial of service.
  • Affects web apps, DB admin tools, ORM inspectors, and SQL APIs.
  • No authentication required; attacker can degrade or block service.

🎯Let’s Practice Exploiting & Learn Patching For Free:

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top