{"id":"CVE-2023-30608","aliases":["GHSA-rrm6-wvj7-cwh2","PYSEC-2023-87"],"url":"https://o3.security/vulnerability/CVE-2023-30608","summary":"Parser contains an inefficient regular expression in sqlparse","details":"sqlparse is a non-validating SQL parser module for Python. In affected versions the SQL parser contains a regular expression that is vulnerable to ReDoS (Regular Expression Denial of Service). This issue was introduced by commit `e75e358`. The vulnerability may lead to Denial of Service (DoS). This issues has been fixed in sqlparse 0.4.4 by commit `c457abd5f`. Users are advised to upgrade. There are no known workarounds for this issue.","published":"2023-04-18T21:32:11.145Z","modified":"2026-08-12T03:51:45.251375663Z","cvss":{"score":5.5,"severity":"MEDIUM","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"},"epss":{"score":0.0098,"percentile":0.5986,"asOf":"2026-09-03"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"sqlparse","fixedVersion":"0.4.4"}],"fix":{"url":"https://github.com/andialbrecht/sqlparse/commit/c457abd5f097dd13fb21543381e7cfafe7d31cfb","label":"andialbrecht/sqlparse@c457abd"},"references":[{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2023/05/msg00017.html"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2024/12/msg00022.html"},{"type":"WEB","url":"https://owasp.org/www-community/attacks/Regular_expression_Denial_of_Service_-_ReDoS"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/30xxx/CVE-2023-30608.json"},{"type":"ADVISORY","url":"https://github.com/andialbrecht/sqlparse/security/advisories/GHSA-rrm6-wvj7-cwh2"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-30608"},{"type":"FIX","url":"https://github.com/andialbrecht/sqlparse/commit/c457abd5f097dd13fb21543381e7cfafe7d31cfb"},{"type":"FIX","url":"https://github.com/andialbrecht/sqlparse/commit/e75e35869473832a1eb67772b1adfee2db11b85a"},{"type":"PACKAGE","url":"https://github.com/andialbrecht/sqlparse"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/sqlparse/PYSEC-2023-87.yaml"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:45.251375663Z"}}