CVE Feed

    Dashboard / CVE / CVE-2021-32839

    CVE-2021-32839

    sqlparse is a non-validating SQL parser module for Python. In sqlparse versions 0.4.0 and 0.4.1 there is a regular Expression Denial of Service in sqlparse vulnerability. The regular expression may cause exponential backtracking on strings containing many repetitions of '\r\n' in SQL comments. Only the formatting feature that removes comments from SQL statements is affected by this regular expression. As a workaround don't use the sqlformat.format function with keyword strip_comments=True or the --strip-comments command line flag when using the sqlformat command line tool. The issues has been fixed in sqlparse 0.4.2.

    Published:Sep 10, 2021
    Last Modified:Nov 3, 2025
    EPS:Sep 20, 2021
    EPSS Score:0.00109
    CVSS Score:7.5

    Affected Products

    Vendor
    Redhat
    Product
    Satellite
    Vendor
    Redhat
    Product
    Satellite Capsule
    Vendor
    Sqlparse Project
    Product
    Sqlparse

    Exploits

    No exploit reference

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High