Executive brief
sqlparse is a Python library that parses SQL statements. When processing SQL input containing deeply nested brackets, the parsing logic triggers uncontrolled recursion that exhausts the application's stack, causing it to crash. Any application using sqlparse to parse untrusted SQL input is vulnerable to denial of service.
Technical details
The vulnerability is an uncontrolled recursion flaw (CWE-674) in the flatten() method of the TokenList class. When parsing heavily nested bracket structures (e.g., thousands of nested square brackets), the recursive flatten() function is called repeatedly without depth limits, exhausting the call stack and raising a RecursionError. The attack vector is network-based with no authentication or user interaction required—any caller of sqlparse.parse() with attacker-controlled input can trigger the crash. The fix, available in version 0.5.0, implements a maximum recursion depth check that raises an exception before stack exhaustion occurs.
Affected products
- sqlparse sqlparse before 0.5.0
Timeline
- 2024-04-15: disclosed
- 2024-04-15: patched: Fix released in version 0.5.0