<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T13:26:57.028109+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-athenacli-cve-2026-59894</id>
    <title>BREW-athenacli-CVE-2026-59894 — sqlparse: Generated Python and PHP snippets allow SQL string breakout through unescaped backslashes</title>
    <updated>2026-10-03T13:26:57.296444+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: athenacli</p>
<p>### Summary</p>
<p>The documented Python and PHP output modes generate source-code snippets from caller-supplied SQL. Their output filters escape quote characters without first escaping existing backslashes. Crafted SQL can therefore neutralize the generated quote escape, terminate the intended language string, and place attacker-controlled code into the generated snippet. If a downstream consumer executes or imports that generated source, the injected code runs in the consumer's environment.</p>
<p>### Details</p>
<p>The Python output filter places SQL in a single-quoted string and replaces each single quote with an escaped quote. The PHP output filter performs the equivalent operation for a double-quoted string. Neither transformation escapes pre-existing backslashes before escaping quotes. A backslash supplied immediately before a quote causes the generated backslash to be escaped instead of the quote, allowing the quote to close the string.</p>
<p>The affected modes are exposed through `sqlparse.format(..., output_format='python')`, `sqlparse.format(..., output_format='php')`, and the corresponding `sqlformat -l` options. Formatting produces the injected source but does not itself execute it; code execution occurs when a downstream workflow treats the generated snippet as Python or PHP code.</p>
<p>Relevant code locations:</p>
<p>- `sqlparse/formatter.py:193` — selection of the output-language filters
- `sqlparse/filters/output.py:45` — opening of the generated Python string
- `sqlparse/filters/output.py:6…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-athenacli-cve-2026-59894"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1165</id>
    <title>certfr-2026-avi-1165 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
    <updated>2026-10-03T13:26:57.296541+00:00</updated>
    <content>certfr-2026-avi-1165</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-1165"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-ec11110</id>
    <title>Withdrawn: CLEANSTART-2026-EC11110 — undici's retry interceptor can append the body of a ranged retry response to bytes already delivered from an earlier pa…</title>
    <updated>2026-10-03T13:26:57.296565+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: apache-superset</p>
<p>Multiple security vulnerabilities affect the apache-superset package. undici's retry interceptor can append the body of a ranged retry response to bytes already delivered from an earlier partial response while still presenting the original response's status and headers. See references for individual vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-ec11110"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-354743</id>
    <title>EUVD-2026-354743</title>
    <updated>2026-10-03T13:26:57.296591+00:00</updated>
    <content>EUVD-2026-354743</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-354743"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-59894</id>
    <title>fkie_cve-2026-59894</title>
    <updated>2026-10-03T13:26:57.296619+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>sqlparse is a non-validating SQL parser module for Python. Prior to 0.6.0, sqlparse/filters/output.py fails to escape existing backslashes before quotes in sqlparse.format output_format='python' and output_format='php' and the corresponding sqlformat -l modes, allowing crafted SQL to terminate the generated string and inject Python or PHP code when a downstream consumer executes or imports the generated source. This issue is fixed in version 0.6.0.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-59894"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-3496-9g83-7v6x</id>
    <title>GHSA-3496-9g83-7v6x — sqlparse: Generated Python and PHP snippets allow SQL string breakout through unescaped backslashes</title>
    <updated>2026-10-03T13:26:57.296651+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: sqlparse</p>
<p>### Summary</p>
<p>The documented Python and PHP output modes generate source-code snippets from caller-supplied SQL. Their output filters escape quote characters without first escaping existing backslashes. Crafted SQL can therefore neutralize the generated quote escape, terminate the intended language string, and place attacker-controlled code into the generated snippet. If a downstream consumer executes or imports that generated source, the injected code runs in the consumer's environment.</p>
<p>### Details</p>
<p>The Python output filter places SQL in a single-quoted string and replaces each single quote with an escaped quote. The PHP output filter performs the equivalent operation for a double-quoted string. Neither transformation escapes pre-existing backslashes before escaping quotes. A backslash supplied immediately before a quote causes the generated backslash to be escaped instead of the quote, allowing the quote to close the string.</p>
<p>The affected modes are exposed through `sqlparse.format(..., output_format='python')`, `sqlparse.format(..., output_format='php')`, and the corresponding `sqlformat -l` options. Formatting produces the injected source but does not itself execute it; code execution occurs when a downstream workflow treats the generated snippet as Python or PHP code.</p>
<p>Relevant code locations:</p>
<p>- `sqlparse/formatter.py:193` — selection of the output-language filters
- `sqlparse/filters/output.py:45` — opening of the generated Python string
- `sqlparse/filters/output.py:6…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-3496-9g83-7v6x"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-4218</id>
    <title>OESA-2026-4218 — python-sqlparse security update</title>
    <updated>2026-10-03T13:26:57.296699+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:24.03-LTS-SP3: python-sqlparse</p>
<p>A non-validating SQL parser.

Security Fix(es):</p>
<p>sqlparse is a non-validating SQL parser module for Python. Prior to 0.6.0, TokenList construction and string conversion in sqlparse/sql.py repeatedly flatten nested token subtrees constructed by group_parenthesis and group_case, causing quadratic CPU consumption through sqlparse.parse(), sqlparse.format(), and sqlparse.split() before depth and token limits terminate processing. This issue is fixed in version 0.6.0.(CVE-2026-54284)</p>
<p>sqlparse is a non-validating SQL parser module for Python. Prior to 0.6.0, sqlparse/filters/output.py fails to escape existing backslashes before quotes in sqlparse.format output_format=&amp;apos;python&amp;apos; and output_format=&amp;apos;php&amp;apos; and the corresponding sqlformat -l modes, allowing crafted SQL to terminate the generated string and inject Python or PHP code when a downstream consumer executes or imports the generated source. This issue is fixed in version 0.6.0.(CVE-2026-59894)</p>
<p>sqlparse is a non-validating SQL parser module for Python. Prior to 0.6.0, group_comments in sqlparse/engine/grouping.py repeatedly rescans comment-only statements before the MAX_GROUPING_TOKENS guard, causing quadratic CPU consumption through sqlparse.parse() and sqlparse.format(sql, strip_comments=True). This issue is fixed in version 0.6.0.(CVE-2026-71491)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-4218"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11557-1</id>
    <title>openSUSE-SU-2026:11557-1 — python313-sqlparse-0.6.0-1.1 on GA media</title>
    <updated>2026-10-03T13:26:57.296729+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>python313-sqlparse-0.6.0-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:11557-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2026-3696</id>
    <title>PYSEC-2026-3696 — sqlparse: Generated Python and PHP snippets allow SQL string breakout through unescaped backslashes</title>
    <updated>2026-10-03T13:26:57.296749+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: sqlparse</p>
<p>### Summary</p>
<p>The documented Python and PHP output modes generate source-code snippets from caller-supplied SQL. Their output filters escape quote characters without first escaping existing backslashes. Crafted SQL can therefore neutralize the generated quote escape, terminate the intended language string, and place attacker-controlled code into the generated snippet. If a downstream consumer executes or imports that generated source, the injected code runs in the consumer's environment.</p>
<p>### Details</p>
<p>The Python output filter places SQL in a single-quoted string and replaces each single quote with an escaped quote. The PHP output filter performs the equivalent operation for a double-quoted string. Neither transformation escapes pre-existing backslashes before escaping quotes. A backslash supplied immediately before a quote causes the generated backslash to be escaped instead of the quote, allowing the quote to close the string.</p>
<p>The affected modes are exposed through `sqlparse.format(..., output_format='python')`, `sqlparse.format(..., output_format='php')`, and the corresponding `sqlformat -l` options. Formatting produces the injected source but does not itself execute it; code execution occurs when a downstream workflow treats the generated snippet as Python or PHP code.</p>
<p>Relevant code locations:</p>
<p>- `sqlparse/formatter.py:193` — selection of the output-language filters
- `sqlparse/filters/output.py:45` — opening of the generated Python string
- `sqlparse/filters/output.py:6…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2026-3696"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:23561-1</id>
    <title>SUSE-SU-2026:23561-1 — Security update for python-sqlparse</title>
    <updated>2026-10-03T13:26:57.296794+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for python-sqlparse</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:23561-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-59894</id>
    <title>UBUNTU-CVE-2026-59894</title>
    <updated>2026-10-03T13:26:57.296812+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:16.04:LTS: sqlparse, Ubuntu:Pro:18.04:LTS: sqlparse, Ubuntu:Pro:20.04:LTS: sqlparse, Ubuntu:22.04:LTS: sqlparse, Ubuntu:24.04:LTS: sqlparse, Ubuntu:26.04:LTS: sqlparse</p>
<p>sqlparse is a non-validating SQL parser module for Python. Prior to 0.6.0, sqlparse/filters/output.py fails to escape existing backslashes before quotes in sqlparse.format output_format='python' and output_format='php' and the corresponding sqlformat -l modes, allowing crafted SQL to terminate the generated string and inject Python or PHP code when a downstream consumer executes or imports the generated source. This issue is fixed in version 0.6.0.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-59894"/>
  </entry>
</feed>
