| Name | CVE-2026-46373 |
| Description | SQLFluff is a modular SQL linter and auto-formatter with support for multiple dialects and templated code. Prior to version 4.1.0, in deployments where untrusted users can provide SQL queries to be linted, an untrusted user can submit a malicious query with deliberate excessive nesting to any application using the parser to trigger a Denial of Service through resource exhaustion. This issue has been patched in version 4.1.0. |
| Source | CVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
| Debian Bugs | 1139640 |
Vulnerable and fixed packages
The table below lists information on source packages.
| Source Package | Release | Version | Status |
|---|
| sqlfluff (PTS) | bookworm | 1.4.5-2 | vulnerable |
| trixie | 3.3.1-1 | vulnerable |
| forky, sid | 3.5.0-2 | vulnerable |
The information below is based on the following data on fixed versions.
| Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
|---|
| sqlfluff | source | (unstable) | (unfixed) | | | 1139640 |
Notes
[trixie] - sqlfluff <no-dsa> (Minor issue)
[bookworm] - sqlfluff <postponed> (Parser resource-exhaustion DoS, only reachable where untrusted SQL is linted; upstream fix adds new parse limits that do not apply to the pre-3.0 parser in 1.4.5)
https://github.com/sqlfluff/sqlfluff/security/advisories/GHSA-wmhf-fqc8-vxhh