CVE Vulnerabilities

CVE-2026-71491

Uncontrolled Resource Consumption

Published: Aug 17, 2026 | Modified: Sep 09, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
7.5 IMPORTANT
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

sqlparse is a non-validating SQL parser module for Python. Prior to 0.6.0, group_comments in sqlparse/engine/grouping.py repeatedly rescans comment-only statements before the MAX_GROUPING_TOKENS guard, causing quadratic CPU consumption through sqlparse.parse() and sqlparse.format(sql, strip_comments=True). This issue is fixed in version 0.6.0.

Weakness

The product does not properly control the allocation and maintenance of a limited resource.

Affected Software

NameVendorStart VersionEnd Version
Red Hat Ansible Automation Platform 2.5 for RHEL 8RedHatpython3.12-sqlparse-0:0.6.0-1.el8ap*
Red Hat Ansible Automation Platform 2.5 for RHEL 9RedHatpython3.12-sqlparse-0:0.6.0-1.el9ap*
Red Hat Ansible Automation Platform 2.6 for RHEL 10RedHatpython-sqlparse-0:0.6.0-1.el10ap*
Red Hat Ansible Automation Platform 2.6 for RHEL 9RedHatpython3.12-sqlparse-0:0.6.0-1.el9ap*
Red Hat Ansible Automation Platform 2.7 for RHEL 10RedHatpython-sqlparse-0:0.6.0-1.el10ap*
Red Hat Ansible Automation Platform 2.7 for RHEL 9RedHatpython3.12-sqlparse-0:0.6.0-1.el9ap*
Red Hat Satellite 6.18 for RHEL 9RedHatpython3.12-sqlparse-0:0.6.0-1.el9pc*
Red Hat Satellite 6.18 for RHEL 9RedHatpython3.12-sqlparse-0:0.6.0-1.el9pc*
Red Hat Satellite 6.19 for RHEL 9RedHatpython3.12-sqlparse-0:0.6.0-1.el9pc*
Red Hat Satellite 6.19 for RHEL 9RedHatpython3.12-sqlparse-0:0.6.0-1.el9pc*
Red Hat Ansible Automation Platform 2.5RedHatansible-automation-platform-25/gateway-rhel8:1789605572*
Red Hat Ansible Automation Platform 2.5RedHatansible-automation-platform-25/hub-rhel8:1789606395*
Red Hat Ansible Automation Platform 2.5RedHatansible-automation-platform-25/lightspeed-rhel8:1789685837*
Red Hat Ansible Automation Platform 2.6RedHatansible-automation-platform-26/eda-controller-rhel9:1789653608*
Red Hat Ansible Automation Platform 2.6RedHatansible-automation-platform-26/gateway-rhel9:1789666472*
Red Hat Ansible Automation Platform 2.6RedHatansible-automation-platform-26/hub-rhel9:1789611274*
Red Hat Ansible Automation Platform 2.6RedHatansible-automation-platform-26/lightspeed-rhel9:1789656884*
Red Hat Ansible Automation Platform 2.6RedHatansible-automation-platform-tech-preview/metrics-service-rhel9:1789654558*
Red Hat Ansible Automation Platform 2.7RedHatansible-automation-platform-27/eda-controller-rhel9:1788917355*
Red Hat Ansible Automation Platform 2.7RedHatansible-automation-platform-27/gateway-rhel9:1788918510*
Red Hat Ansible Automation Platform 2.7RedHatansible-automation-platform-27/lightspeed-rhel9:1788916677*
Red Hat Ansible Automation Platform 2.7RedHatansible-automation-platform-27/metrics-service-rhel9:1788917058*
Red Hat Ansible Automation Platform 2.7RedHatansible-automation-platform-27/hub-rhel9:1789572632*
Red Hat Discovery 2RedHatdiscovery/discovery-server-rhel9:1788205779*
Red Hat Discovery 2RedHatdiscovery/discovery-server-rhel9:1789675186*
Red Hat OpenShift AI 3.5RedHatrhoai/odh-training-cuda128-torch29-py312-rhel9:1789529851*
Red Hat Satellite 6.18RedHatsatellite/iop-advisor-backend-rhel9:1789666499*
Red Hat Satellite 6.19RedHatsatellite/iop-advisor-backend-rhel9:1789666498*
SqlparseUbuntudevel*
SqlparseUbuntuesm-infra-legacy/xenial*
SqlparseUbuntuesm-infra/bionic*
SqlparseUbuntuesm-infra/focal*
SqlparseUbuntujammy*
SqlparseUbuntunoble*
SqlparseUbunturesolute*
SqlparseUbuntuupstream*

Potential Mitigations

  • Mitigation of resource exhaustion attacks requires that the target system either:

  • The first of these solutions is an issue in itself though, since it may allow attackers to prevent the use of the system by a particular valid user. If the attacker impersonates the valid user, they may be able to prevent the user from accessing the server in question.

  • The second solution is simply difficult to effectively institute – and even when properly done, it does not provide a full solution. It simply makes the attack require more resources on the part of the attacker.

References