SQLFluff: Recursive Stack Overflow in Parser
Description
Published to the GitHub Advisory Database
May 19, 2026
Reviewed
May 19, 2026
Published by the National Vulnerability Database
Jun 9, 2026
Last updated
Jul 6, 2026
Impact
In deployments where untrusted users can provide SQL queries to be linted, an untrusted user can submit a malicious query with deliberate excessive nesting to any application using the parser to trigger a Denial of Service through resource exhaustion.
Patches
Versions 4.1.0 and up contain a configurable recursion limit, which is enabled by default, to prevent this manner of exploit.
Credit
Ori Nakar from Imperva Threat Research Team.
References