<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T12:27:59.163547+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-athenacli-cve-2026-59893</id>
    <title>BREW-athenacli-CVE-2026-59893 — sqlparse: Inefficient Regex Handling of Dollar-Quoted SQL Literals Leads to ReDoS (Denial of Service)</title>
    <updated>2026-10-03T12:27:59.750802+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: athenacli</p>
<p>### Summary</p>
<p>sqlparse contains a Regular Expression Denial of Service (ReDoS) vulnerability in its dollar-quoted SQL literal lexer. The regex pattern at `sqlparse/keywords.py:33` uses a backreference (`\1`) to match closing dollar-quote delimiters, causing O(n²) CPU complexity when processing inputs containing many unique, unmatched dollar-quote opening sequences. An attacker who can supply arbitrary SQL text to any application using sqlparse can trigger sustained CPU exhaustion, resulting in a denial of service. No authentication or special privileges are required.</p>
<p>**Scope note:** the same regex shape — a lazy dot-all quantifier terminated by a delimiter, applied at every input position by the lexer loop — is also present in the two multiline-comment patterns. Those are covered by this advisory and by the same fix; see "Additional affected pattern: multiline comments" below.</p>
<p>### Details</p>
<p>The vulnerable regex is defined in `sqlparse/keywords.py` as part of `SQL_REGEX`:</p>
<p>```python
# sqlparse/keywords.py:33
(r'((?&lt;![\w\"\$])\$(?:[_A-ZÀ-Ü]\w*)?\$)[\s\S]*?\1', tokens.Literal),
```</p>
<p>This pattern first captures a dollar-quote delimiter (e.g., `$tag$`) into group 1, then attempts to match any characters (`[\s\S]*?`) up to the same delimiter again via backreference `\1`. When no matching closing delimiter exists, the regex engine exhausts the remaining input before concluding there is no match. For a sequence of N unique unmatched openers, each opener triggers a full scan of the r…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-athenacli-cve-2026-59893"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1165</id>
    <title>certfr-2026-avi-1165 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
    <updated>2026-10-03T12:27:59.750968+00:00</updated>
    <content>certfr-2026-avi-1165</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-1165"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-ec11110</id>
    <title>Withdrawn: CLEANSTART-2026-EC11110 — undici's retry interceptor can append the body of a ranged retry response to bytes already delivered from an earlier pa…</title>
    <updated>2026-10-03T12:27:59.750993+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: apache-superset</p>
<p>Multiple security vulnerabilities affect the apache-superset package. undici's retry interceptor can append the body of a ranged retry response to bytes already delivered from an earlier partial response while still presenting the original response's status and headers. See references for individual vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-ec11110"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-354534</id>
    <title>EUVD-2026-354534</title>
    <updated>2026-10-03T12:27:59.751019+00:00</updated>
    <content>EUVD-2026-354534</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-354534"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-59893</id>
    <title>fkie_cve-2026-59893</title>
    <updated>2026-10-03T12:27:59.751032+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>sqlparse is a non-validating SQL parser module for Python. Prior to 0.6.0, SQL_REGEX in sqlparse/keywords.py and the per-position loop in sqlparse/lexer.py repeatedly scan unmatched dollar-quoted literal and multiline-comment delimiters, causing quadratic CPU consumption through sqlparse.parse(), sqlparse.format(), and sqlparse.split(). This issue is fixed in version 0.6.0.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-59893"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-prg7-hcfm-mfcr</id>
    <title>GHSA-prg7-hcfm-mfcr — sqlparse: Inefficient Regex Handling of Dollar-Quoted SQL Literals Leads to ReDoS (Denial of Service)</title>
    <updated>2026-10-03T12:27:59.751055+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: sqlparse</p>
<p>### Summary</p>
<p>sqlparse contains a Regular Expression Denial of Service (ReDoS) vulnerability in its dollar-quoted SQL literal lexer. The regex pattern at `sqlparse/keywords.py:33` uses a backreference (`\1`) to match closing dollar-quote delimiters, causing O(n²) CPU complexity when processing inputs containing many unique, unmatched dollar-quote opening sequences. An attacker who can supply arbitrary SQL text to any application using sqlparse can trigger sustained CPU exhaustion, resulting in a denial of service. No authentication or special privileges are required.</p>
<p>**Scope note:** the same regex shape — a lazy dot-all quantifier terminated by a delimiter, applied at every input position by the lexer loop — is also present in the two multiline-comment patterns. Those are covered by this advisory and by the same fix; see "Additional affected pattern: multiline comments" below.</p>
<p>### Details</p>
<p>The vulnerable regex is defined in `sqlparse/keywords.py` as part of `SQL_REGEX`:</p>
<p>```python
# sqlparse/keywords.py:33
(r'((?&lt;![\w\"\$])\$(?:[_A-ZÀ-Ü]\w*)?\$)[\s\S]*?\1', tokens.Literal),
```</p>
<p>This pattern first captures a dollar-quote delimiter (e.g., `$tag$`) into group 1, then attempts to match any characters (`[\s\S]*?`) up to the same delimiter again via backreference `\1`. When no matching closing delimiter exists, the regex engine exhausts the remaining input before concluding there is no match. For a sequence of N unique unmatched openers, each opener triggers a full scan of the r…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-prg7-hcfm-mfcr"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-3547</id>
    <title>OESA-2026-3547 — python-sqlparse security update</title>
    <updated>2026-10-03T12:27:59.751137+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:22.03-LTS-SP4: python-sqlparse, openEuler:24.03-LTS-SP1: python-sqlparse, openEuler:24.03-LTS-SP3: python-sqlparse, openEuler:24.03-LTS-SP4: python-sqlparse, openEuler:20.03-LTS-SP4: python-sqlparse</p>
<p>A non-validating SQL parser.

Security Fix(es):</p>
<p>### Summary</p>
<p>sqlparse contains a Regular Expression Denial of Service (ReDoS) vulnerability in its dollar-quoted SQL literal lexer. The regex pattern at `sqlparse/keywords.py:33` uses a backreference (`\1`) to match closing dollar-quote delimiters, causing O(n²) CPU complexity when processing inputs containing many unique, unmatched dollar-quote opening sequences. An attacker who can supply arbitrary SQL text to any application using sqlparse can trigger sustained CPU exhaustion, resulting in a denial of service. No authentication or special privileges are required.</p>
<p>**Scope note:** the same regex shape — a lazy dot-all quantifier terminated by a delimiter, applied at every input position by the lexer loop — is also present in the two multiline-comment patterns. Those are covered by this advisory and by the same fix; see &amp;quot;Additional affected pattern: multiline comments&amp;quot; below.</p>
<p>### Details</p>
<p>The vulnerable regex is defined in `sqlparse/keywords.py` as part of `SQL_REGEX`:</p>
<p>```python
# sqlparse/keywords.py:33
(r&amp;apos;((?&amp;lt;![\w\&amp;quot;\$])\$(?:[_A-ZÀ-Ü]\w*)?\$)[\s\S]*?\1&amp;apos;, tokens.Literal),
```</p>
<p>This pattern first captures a dollar-quote delimiter (e.g., `$tag$`) into group 1, then attempts to match any characters (`[\s\S]*?`) up to the same delimiter again via backreference `\1`. When no matching closing delimiter exists, the regex engine exhausts the remaining input before concluding there is no match. For a se…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-3547"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11557-1</id>
    <title>openSUSE-SU-2026:11557-1 — python313-sqlparse-0.6.0-1.1 on GA media</title>
    <updated>2026-10-03T12:27:59.751194+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>python313-sqlparse-0.6.0-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:11557-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2026-3698</id>
    <title>PYSEC-2026-3698 — sqlparse: Inefficient Regex Handling of Dollar-Quoted SQL Literals Leads to ReDoS (Denial of Service)</title>
    <updated>2026-10-03T12:27:59.751227+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: sqlparse</p>
<p>### Summary</p>
<p>sqlparse contains a Regular Expression Denial of Service (ReDoS) vulnerability in its dollar-quoted SQL literal lexer. The regex pattern at `sqlparse/keywords.py:33` uses a backreference (`\1`) to match closing dollar-quote delimiters, causing O(n²) CPU complexity when processing inputs containing many unique, unmatched dollar-quote opening sequences. An attacker who can supply arbitrary SQL text to any application using sqlparse can trigger sustained CPU exhaustion, resulting in a denial of service. No authentication or special privileges are required.</p>
<p>**Scope note:** the same regex shape — a lazy dot-all quantifier terminated by a delimiter, applied at every input position by the lexer loop — is also present in the two multiline-comment patterns. Those are covered by this advisory and by the same fix; see "Additional affected pattern: multiline comments" below.</p>
<p>### Details</p>
<p>The vulnerable regex is defined in `sqlparse/keywords.py` as part of `SQL_REGEX`:</p>
<p>```python
# sqlparse/keywords.py:33
(r'((?&lt;![\w\"\$])\$(?:[_A-ZÀ-Ü]\w*)?\$)[\s\S]*?\1', tokens.Literal),
```</p>
<p>This pattern first captures a dollar-quote delimiter (e.g., `$tag$`) into group 1, then attempts to match any characters (`[\s\S]*?`) up to the same delimiter again via backreference `\1`. When no matching closing delimiter exists, the regex engine exhausts the remaining input before concluding there is no match. For a sequence of N unique unmatched openers, each opener triggers a full scan of the r…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2026-3698"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:61783</id>
    <title>RHSA-2026:61783 — Red Hat Security Advisory: A Subscription Management tool for finding and reporting Red Hat product usage</title>
    <updated>2026-10-03T12:27:59.751308+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>webpack-dev-middleware: lack of URL validation may lead to file leak curl: curl: Authentication bypass due to incorrect connection reuse with Negotiate authentication curl: curl: Information disclosure via OAuth2 bearer token leakage during HTTP(S) redirect tar: tar: Hidden file injection via crafted archives fast-uri: fast-uri: URI authority bypass due to improper delimiter handling libxml2: mingw-libxml2: libxml2: Denial of Service via crafted XML input due to use-after-free curl: curl: Insecure connection establishment due to TLS configuration mismatch curl: curl: Man-in-the-middle attack via SSH host key bypass sqlite: SQLite: Arbitrary code execution via crafted FTS5 full-text search data sqlite: SQLite: Arbitrary code execution and crash via heap-based buffer overflow in FTS5 libxml2: libxml2: Arbitrary code execution in xmlcatalog utility via buffer overflow libarchive: Double-Free Vulnerability in RAR5 Decompression Logic via dangling filtered_buf pointer in init_unpack() GDBusServer: glib2: GDBusServer pre-authentication DoS via unbounded SASL line buffering tar: tar: TOCTOU in incremental dumpdir 'X' rename handling allows restore path escape tar: tar: --one-top-level hardlink targets not confined to top-level directory enabling arbitrary file overwrite gzip: gzip: Arbitrary file overwrite via insecure temporary file handling in gzexe utility gzip: gzip: Information disclosure via global buffer overflow in LZH decompression python-idna: idna: Denial of Service via…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:61783"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:23561-1</id>
    <title>SUSE-SU-2026:23561-1 — Security update for python-sqlparse</title>
    <updated>2026-10-03T12:27:59.751397+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for python-sqlparse</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:23561-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-59893</id>
    <title>UBUNTU-CVE-2026-59893</title>
    <updated>2026-10-03T12:27:59.751416+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:18.04:LTS: sqlparse, Ubuntu:Pro:20.04:LTS: sqlparse, Ubuntu:22.04:LTS: sqlparse, Ubuntu:24.04:LTS: sqlparse, Ubuntu:26.04:LTS: sqlparse</p>
<p>sqlparse is a non-validating SQL parser module for Python. Prior to 0.6.0, SQL_REGEX in sqlparse/keywords.py and the per-position loop in sqlparse/lexer.py repeatedly scan unmatched dollar-quoted literal and multiline-comment delimiters, causing quadratic CPU consumption through sqlparse.parse(), sqlparse.format(), and sqlparse.split(). This issue is fixed in version 0.6.0.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-59893"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3555</id>
    <title>WID-SEC-W-2026-3555 — Red Hat Ansible Automation Platform (automation-controller): Mehrere Schwachstellen</title>
    <updated>2026-10-03T12:27:59.751442+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Red Hat Ansible Automation Platform ausnutzen, um seine Privilegien zu erhöhen, beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren oder offenzulegen und einen Denial-of-Service-Zustand herbeizuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3555"/>
  </entry>
</feed>
