PT-2026-42043 · Pypi · Sqlfluff

Published

2026-05-19

·

Updated

2026-05-26

·

CVE-2026-46374

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Impact

In deployments where untrusted users can provide SQL queries to be linted, an untrusted user can submit a malicious long query to any application using the parser to trigger a Denial of Service through resource exhaustion.

Patches

Versions 4.2.0 and up contain a configurable parse node limit, which is enabled by default, to prevent this manner of exploit.

Credit

Ori Nakar from Imperva Threat Research Team.

Fix

Resource Exhaustion

Weakness Enumeration

Related Identifiers

CVE-2026-46374
GHSA-73JC-5MRQ-PRW7

Affected Products

Sqlfluff