sqlfluff CVE Vulnerabilities & CVE List (3)

Products (CPE): — CVEs: 3

sqlfluff vulnerability overview

Aggregates CVE and security vulnerability intelligence across all sqlfluff-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.

Disclosed issues often relate to vendor risk denial of service and vendor risk sql injection; exposure may include vendor impact application crash in vendor surface software deployment contexts.

Vulnerability distribution trend (last 24 months)

Showing 13 of 3 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2026-46374 SQLFluff is a modular SQL linter and auto-formatter with support for multiple dialects and templated code. Prior to version 4.2.0, in deployments where untrusted users can provide SQL queries to be linted, an untrusted user can submit a malicious long query to any application using the parser to trigger a Denial of Service through resource exhaustion. This issue has been patched in version 4.2.0. [email protected] 7.5 0.26% 2026-06-09 2026-06-17
CVE-2026-46373 SQLFluff is a modular SQL linter and auto-formatter with support for multiple dialects and templated code. Prior to version 4.1.0, in deployments where untrusted users can provide SQL queries to be linted, an untrusted user can submit a malicious query with deliberate excessive nesting to any application using the parser to trigger a Denial of Service through resource exhaustion. This issue has been patched in version 4.1.0. [email protected] 7.5 0.26% 2026-06-09 2026-06-17
CVE-2023-36830 SQLFluff is a SQL linter. Prior to version 2.1.2, in environments where untrusted users have access to the config files, there is a potential security vulnerability where those users could use the `library_path` config value to allow arbitrary python code to be executed via macros. For many users who use SQLFluff in the context of an environment where all users already have fairly escalated privileges, this may not be an issue - however in larger user bases, or where SQLFluff is bundled into ano [email protected] 6.3 0.39% 2023-07-06 2026-06-17
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence