Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3042▲ 436 respecto a la semana anterior
Críticas / altas1431▲ 190 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)383▲ 168 respecto a la semana anterior
10 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (8.7) | 0.67% | — | Temporalio SqlparserAITemporalAI | 21/9/2026 | 22/9/2026 | temporalio/sqlparser accepts SQL containing deeply nested unary expressions and can return a correspondingly deep abstract syntax tree without enforcing an applicable nesting limit. The library's String and Walk operations recursively traverse that tree. An application that parses attacker-controlled SQL and later… | |
| Pendiente de análisis | Alta (8.7) | 0.39% | — | Temporalio SqlparserAITemporalAI | 21/9/2026 | 22/9/2026 | temporalio/sqlparser can panic when Parse, ParseStrictDDL, or ParseNext processes a MySQL version comment whose contents are empty or consist only of one to five decimal digits. ExtractMysqlComment does not check the -1 result returned by strings.IndexFunc before using it as a slice boundary. The resulting Go runtime… | |
| Aplazada | Media (5.1) | 0.18% | — | SqlparseAI | 1/9/2026 | 9/9/2026 | sqlparse is a non-validating SQL parser module for Python. Prior to 0.6.0, sqlparse.format(sql, reindent=True) and sqlformat --reindent route attacker-controlled parenthesized tuple lists through ReindentFilter._get_offset() in sqlparse/filters/reindent.py, where _flatten_up_to_token() repeatedly rebuilds and joins… | |
| Aplazada | Alta (8.7) | 0.26% | — | SqlparseAI | 17/8/2026 | 9/9/2026 | sqlparse is a non-validating SQL parser module for Python. Prior to 0.6.0, group_comments in sqlparse/engine/grouping.py repeatedly rescans comment-only statements before the MAX_GROUPING_TOKENS guard, causing quadratic CPU consumption through sqlparse.parse() and sqlparse.format(sql, strip_comments=True). This issue… | |
| Aplazada | Media (6.2) | 0.18% | — | SqlparseAI | 17/8/2026 | 18/9/2026 | sqlparse is a non-validating SQL parser module for Python. Prior to 0.6.0, sqlparse/filters/output.py fails to escape existing backslashes before quotes in sqlparse.format output_format='python' and output_format='php' and the corresponding sqlformat -l modes, allowing crafted SQL to terminate the generated string and… | |
| Aplazada | Alta (7.5) | 0.34% | — | SqlparseAI | 17/8/2026 | 18/9/2026 | sqlparse is a non-validating SQL parser module for Python. Prior to 0.6.0, SQL_REGEX in sqlparse/keywords.py and the per-position loop in sqlparse/lexer.py repeatedly scan unmatched dollar-quoted literal and multiline-comment delimiters, causing quadratic CPU consumption through sqlparse.parse(), sqlparse.format(),… | |
| Aplazada | Alta (8.7) | 0.33% | — | SqlparseAI | 17/8/2026 | 18/9/2026 | sqlparse is a non-validating SQL parser module for Python. Prior to 0.6.0, TokenList construction and string conversion in sqlparse/sql.py repeatedly flatten nested token subtrees constructed by group_parenthesis and group_case, causing quadratic CPU consumption through sqlparse.parse(), sqlparse.format(), and… | |
| Aplazada | Alta (7.5) | 3.2% | — | SqlparseAI | 30/4/2024 | 17/6/2026 | Passing a heavily nested list to sqlparse.parse() leads to a Denial of Service due to RecursionError. | |
| Modificada | Alta (7.5) | 0.98% | — | Sqlparse Project SqlparseDebian Linux | 18/4/2023 | 17/6/2026 | sqlparse is a non-validating SQL parser module for Python. In affected versions the SQL parser contains a regular expression that is vulnerable to ReDoS (Regular Expression Denial of Service). This issue was introduced by commit `e75e358`. The vulnerability may lead to Denial of Service (DoS). This issues has been… | |
| Modificada | Alta (7.5) | 2.3% | — | Sqlparse Project Sqlparse | 20/9/2021 | 17/6/2026 | sqlparse is a non-validating SQL parser module for Python. In sqlparse versions 0.4.0 and 0.4.1 there is a regular Expression Denial of Service in sqlparse vulnerability. The regular expression may cause exponential backtracking on strings containing many repetitions of '\r\n' in SQL comments. Only the formatting… |