{"id":"GHSA-27jp-wm6q-gp25","aliases":[],"url":"https://o3.security/vulnerability/GHSA-27jp-wm6q-gp25","summary":"sqlparse: formatting list of tuples leads to denial of service","details":"### Summary\nThe below gist hangs while attempting to format a long list of tuples.\n\nThis was found while [drafting a regression test for Dja\nngo 5.2's composite primary key feature](https://code.djangoproject.com/ticket/36416#comment:3), which allows querying composite fields with tuples.\n\n###","published":"2026-02-13T16:16:11Z","modified":"2026-09-10T03:50:33.710557518Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"sqlparse","fixedVersion":"0.5.4"}],"fix":{"url":"https://github.com/andialbrecht/sqlparse/commit/40ed3aa958657fa4a82055927fa9de70ab903360","label":"andialbrecht/sqlparse@40ed3aa"},"references":[{"type":"WEB","url":"https://github.com/andialbrecht/sqlparse/security/advisories/GHSA-27jp-wm6q-gp25"},{"type":"WEB","url":"https://github.com/andialbrecht/sqlparse/commit/40ed3aa958657fa4a82055927fa9de70ab903360"},{"type":"PACKAGE","url":"https://github.com/andialbrecht/sqlparse"},{"type":"WEB","url":"https://github.com/andialbrecht/sqlparse/releases/tag/0.5.4"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-10T03:50:33.710557518Z"}}