Andi Albrecht sqlparse是Andi Albrecht个人开发者的一个解析SQL语句的库。 Andi Albrecht sqlparse 0.6.0之前版本存在代码注入漏洞,该漏洞源于sqlparse/filters/output.py未能转义引号前的反斜杠,可能导致注入Python或PHP代码。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| andialbrecht | sqlparse | < 0.6.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| andialbrecht | sqlparse | < 0.6.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-71491 | 8.7 HIGH | sqlparse: Quadratic O(n²) DoS in group_comments |
| CVE-2026-54284 | 8.7 HIGH | sqlparse: TokenList.__init__ materializes O(subtree) value per group, causing CPU DoS befo |
| CVE-2026-59893 | 7.5 HIGH | sqlparse: Inefficient Regex Handling of Dollar-Quoted SQL Literals Leads to ReDoS (Denial |
No comments yet