CVE-2026-46373
7.5 HIGHSQLFluff is a modular SQL linter and auto-formatter with support for multiple dialects and templated code
Published: 2026-06-09 · Last updated: 2026-06-09
Severity and scoring
- CVSS
- 7.5 HIGH
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- CWE
- CWE-674
Description
SQLFluff is a modular SQL linter and auto-formatter with support for multiple dialects and templated code. Prior to version 4.1.0, in deployments where untrusted users can provide SQL queries to be linted, an untrusted user can submit a malicious query with deliberate excessive nesting to any application using the parser to trigger a Denial of Service through resource exhaustion. This issue has been patched in version 4.1.0.
Source: NVD
References
Related CVEs
Same CWE
- CVE-2026-9740 — A vulnerability in MongoDB Server's BSON validation logic allows an unauthenticated user to crash the mongod process by sending a special... (7.5 HIGH)
- CVE-2026-49847 — FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implem... (7.5 HIGH)
- CVE-2026-49941 — Net::CIDR::Set versions through 0.20 for Perl did not validate IP addresses (7.5 HIGH)
- CVE-2026-47706 — Strawberry GraphQL is a library for creating GraphQL APIs (5.3 MEDIUM)
- CVE-2026-47320 — Access of uninitialized pointer, Uncontrolled Recursion vulnerability in Samsung Open Source rlottie allows Pointer Manipulation, Oversiz... (6.1 MEDIUM)