SQLFluff: Uncontrolled Resource Consumption in SQLFluff Parser
Description
Published to the GitHub Advisory Database
May 19, 2026
Reviewed
May 19, 2026
Published by the National Vulnerability Database
Jun 9, 2026
Last updated
Jun 10, 2026
Impact
In deployments where untrusted users can provide SQL queries to be linted, an untrusted user can submit a malicious long query to any application using the parser to trigger a Denial of Service through resource exhaustion.
Patches
Versions 4.2.0 and up contain a configurable parse node limit, which is enabled by default, to prevent this manner of exploit.
Credit
Ori Nakar from Imperva Threat Research Team.
References