© 2025-2026 PySpect
First version without a known vulnerability: 0.6.0
sqlparse: Inefficient Regex Handling of Dollar-Quoted SQL Literals Leads to ReDoS (Denial of Service)
Fixed in: 0.6.0
sqlparse: TokenList.__init__ materializes O(subtree) value per group, causing CPU DoS before depth/token caps trigger
Fixed in: 0.6.0
sqlparse: Quadratic O(n²) DoS in group_comments
Fixed in: 0.6.0
sqlparse: Generated Python and PHP snippets allow SQL string breakout through unescaped backslashes
Fixed in: 0.6.0
sqlparse: formatting list of tuples leads to denial of service
Fixed in: 0.5.4
sqlparse parsing heavily nested list leads to Denial of Service
Fixed in: 0.5.0
sqlparse contains a regular expression that is vulnerable to Regular Expression Denial of Service
Fixed in: 0.4.4, c457abd5f097dd13fb21543381e7cfafe7d31cfb, e75e35869473832a1eb67772b1adfee2db11b85a
StripComments filter contains a regular expression that is vulnerable to ReDOS (Regular Expression Denial of Service)
Fixed in: 0.4.2, 8238a9e450ed1524e40cb3a8b0b3c00606903aeb