sqlparse Package Vulnerability: SQL Injection Risk via Unescaped Backslashes
- Severity
- HIGH
- Affected component
- sqlparse (pypi)
- Affected versions
- < 0.5.4 or >= 0.1.0, <= 0.1.0 or >= 0.1.1, <= 0.1.1 or >= 0.1.10, <= 0.1.10 or >= 0.1.11, <= 0.1.11 or >= 0.1.12, <= 0.1.12 or >= 0.1.13, <= 0.1.13 or >= 0.1.14, <= 0.1.14 or >= 0.1.15, <= 0.1.15 or >= 0.1.16, <= 0.1.16 or >= 0.1.17, <= 0.1.17 or >= 0.1.18, <= 0.1.18 or >= 0.1.19, <= 0.1.19 or >= 0.1.2, <= 0.1.2 or >= 0.1.3, <= 0.1.3 or >= 0.1.4, <= 0.1.4 or >= 0.1.5, <= 0.1.5 or >= 0.1.6, <= 0.1.6 or >= 0.1.7, <= 0.1.7 or >= 0.1.8, <= 0.1.8 or >= 0.1.9, <= 0.1.9 or >= 0.2.0, <= 0.2.0 or >= 0.2.1, <= 0.2.1 or >= 0.2.2, <= 0.2.2 or >= 0.2.3, <= 0.2.3 or >= 0.2.4, <= 0.2.4 or >= 0.3.0, <= 0.3.0 or >= 0.3.1, <= 0.3.1 or >= 0.4.0, <= 0.4.0 or >= 0.4.1, <= 0.4.1 or >= 0.4.2, <= 0.4.2 or >= 0.4.3, <= 0.4.3 or >= 0.4.4, <= 0.4.4 or >= 0.5.0, <= 0.5.0 or >= 0.5.1, <= 0.5.1 or >= 0.5.2, <= 0.5.2 or >= 0.5.3, <= 0.5.3 or < 0.5.0 or >= 0.1.0, <= 0.1.0 or >= 0.1.1, <= 0.1.1 or >= 0.1.10, <= 0.1.10 or >= 0.1.11, <= 0.1.11 or >= 0.1.12, <= 0.1.12 or >= 0.1.13, <= 0.1.13 or >= 0.1.14, <= 0.1.14 or >= 0.1.15, <= 0.1.15 or >= 0.1.16, <= 0.1.16 or >= 0.1.17, <= 0.1.17 or >= 0.1.18, <= 0.1.18 or >= 0.1.19, <= 0.1.19 or >= 0.1.2, <= 0.1.2 or >= 0.1.3, <= 0.1.3 or >= 0.1.4, <= 0.1.4 or >= 0.1.5, <= 0.1.5 or >= 0.1.6, <= 0.1.6 or >= 0.1.7, <= 0.1.7 or >= 0.1.8, <= 0.1.8 or >= 0.1.9, <= 0.1.9 or >= 0.2.0, <= 0.2.0 or >= 0.2.1, <= 0.2.1 or >= 0.2.2, <= 0.2.2 or >= 0.2.3, <= 0.2.3 or >= 0.2.4, <= 0.2.4 or >= 0.3.0, <= 0.3.0 or >= 0.3.1, <= 0.3.1 or >= 0.4.0, <= 0.4.0 or >= 0.4.1, <= 0.4.1 or >= 0.4.2, <= 0.4.2 or >= 0.4.3, <= 0.4.3 or >= 0.4.4, <= 0.4.4 or < 0.6.0 or >= 0.1.0, <= 0.1.0 or >= 0.1.1, <= 0.1.1 or >= 0.1.10, <= 0.1.10 or >= 0.1.11, <= 0.1.11 or >= 0.1.12, <= 0.1.12 or >= 0.1.13, <= 0.1.13 or >= 0.1.14, <= 0.1.14 or >= 0.1.15, <= 0.1.15 or >= 0.1.16, <= 0.1.16 or >= 0.1.17, <= 0.1.17 or >= 0.1.18, <= 0.1.18 or >= 0.1.19, <= 0.1.19 or >= 0.1.2, <= 0.1.2 or >= 0.1.3, <= 0.1.3 or >= 0.1.4, <= 0.1.4 or >= 0.1.5, <= 0.1.5 or >= 0.1.6, <= 0.1.6 or >= 0.1.7, <= 0.1.7 or >= 0.1.8, <= 0.1.8 or >= 0.1.9, <= 0.1.9 or >= 0.2.0, <= 0.2.0 or >= 0.2.1, <= 0.2.1 or >= 0.2.2, <= 0.2.2 or >= 0.2.3, <= 0.2.3 or >= 0.2.4, <= 0.2.4 or >= 0.3.0, <= 0.3.0 or >= 0.3.1, <= 0.3.1 or >= 0.4.0, <= 0.4.0 or >= 0.4.1, <= 0.4.1 or >= 0.4.2, <= 0.4.2 or >= 0.4.3, <= 0.4.3 or >= 0.4.4, <= 0.4.4 or >= 0.5.0, <= 0.5.0 or >= 0.5.1, <= 0.5.1 or >= 0.5.2, <= 0.5.2 or >= 0.5.3, <= 0.5.3 or >= 0.5.4, <= 0.5.4 or >= 0.5.5, <= 0.5.5 or < 0.6.0 or >= 0.1.0, <= 0.1.0 or >= 0.1.1, <= 0.1.1 or >= 0.1.10, <= 0.1.10 or >= 0.1.11, <= 0.1.11 or >= 0.1.12, <= 0.1.12 or >= 0.1.13, <= 0.1.13 or >= 0.1.14, <= 0.1.14 or >= 0.1.15, <= 0.1.15 or >= 0.1.16, <= 0.1.16 or >= 0.1.17, <= 0.1.17 or >= 0.1.18, <= 0.1.18 or >= 0.1.19, <= 0.1.19 or >= 0.1.2, <= 0.1.2 or >= 0.1.3, <= 0.1.3 or >= 0.1.4, <= 0.1.4 or >= 0.1.5, <= 0.1.5 or >= 0.1.6, <= 0.1.6 or >= 0.1.7, <= 0.1.7 or >= 0.1.8, <= 0.1.8 or >= 0.1.9, <= 0.1.9 or >= 0.2.0, <= 0.2.0 or >= 0.2.1, <= 0.2.1 or >= 0.2.2, <= 0.2.2 or >= 0.2.3, <= 0.2.3 or >= 0.2.4, <= 0.2.4 or >= 0.3.0, <= 0.3.0 or >= 0.3.1, <= 0.3.1 or >= 0.4.0, <= 0.4.0 or >= 0.4.1, <= 0.4.1 or >= 0.4.2, <= 0.4.2 or >= 0.4.3, <= 0.4.3 or >= 0.4.4, <= 0.4.4 or >= 0.5.0, <= 0.5.0 or >= 0.5.1, <= 0.5.1 or >= 0.5.2, <= 0.5.2 or >= 0.5.3, <= 0.5.3 or >= 0.5.4, <= 0.5.4 or >= 0.5.5, <= 0.5.5 or >= 0.4.0, < 0.4.2 or >= 0.4.0, <= 0.4.0 or >= 0.4.1, <= 0.4.1 or >= 0.1.15, < 0.4.4 or >= 0.1.15, <= 0.1.15 or >= 0.1.16, <= 0.1.16 or >= 0.1.17, <= 0.1.17 or >= 0.1.18, <= 0.1.18 or >= 0.1.19, <= 0.1.19 or >= 0.2.0, <= 0.2.0 or >= 0.2.1, <= 0.2.1 or >= 0.2.2, <= 0.2.2 or >= 0.2.3, <= 0.2.3 or >= 0.2.4, <= 0.2.4 or >= 0.3.0, <= 0.3.0 or >= 0.3.1, <= 0.3.1 or >= 0.4.0, <= 0.4.0 or >= 0.4.1, <= 0.4.1 or >= 0.4.2, <= 0.4.2 or >= 0.4.3, <= 0.4.3 or >= 0.4.0, < 0.4.2 or >= 0.4.0, <= 0.4.0 or >= 0.4.1, <= 0.4.1 or >= 0.1.15, < 0.4.4 or >= 0.1.15, <= 0.1.15 or >= 0.1.16, <= 0.1.16 or >= 0.1.17, <= 0.1.17 or >= 0.1.18, <= 0.1.18 or >= 0.1.19, <= 0.1.19 or >= 0.2.0, <= 0.2.0 or >= 0.2.1, <= 0.2.1 or >= 0.2.2, <= 0.2.2 or >= 0.2.3, <= 0.2.3 or >= 0.2.4, <= 0.2.4 or >= 0.3.0, <= 0.3.0 or >= 0.3.1, <= 0.3.1 or >= 0.4.0, <= 0.4.0 or >= 0.4.1, <= 0.4.1 or >= 0.4.2, <= 0.4.2 or >= 0.4.3, <= 0.4.3 or < 0.5.0 or >= 0.1.0, <= 0.1.0 or >= 0.1.1, <= 0.1.1 or >= 0.1.10, <= 0.1.10 or >= 0.1.11, <= 0.1.11 or >= 0.1.12, <= 0.1.12 or >= 0.1.13, <= 0.1.13 or >= 0.1.14, <= 0.1.14 or >= 0.1.15, <= 0.1.15 or >= 0.1.16, <= 0.1.16 or >= 0.1.17, <= 0.1.17 or >= 0.1.18, <= 0.1.18 or >= 0.1.19, <= 0.1.19 or >= 0.1.2, <= 0.1.2 or >= 0.1.3, <= 0.1.3 or >= 0.1.4, <= 0.1.4 or >= 0.1.5, <= 0.1.5 or >= 0.1.6, <= 0.1.6 or >= 0.1.7, <= 0.1.7 or >= 0.1.8, <= 0.1.8 or >= 0.1.9, <= 0.1.9 or >= 0.2.0, <= 0.2.0 or >= 0.2.1, <= 0.2.1 or >= 0.2.2, <= 0.2.2 or >= 0.2.3, <= 0.2.3 or >= 0.2.4, <= 0.2.4 or >= 0.3.0, <= 0.3.0 or >= 0.3.1, <= 0.3.1 or >= 0.4.0, <= 0.4.0 or >= 0.4.1, <= 0.4.1 or >= 0.4.2, <= 0.4.2 or >= 0.4.3, <= 0.4.3 or >= 0.4.4, <= 0.4.4
- Patched version
- Not yet available
An early warning has been issued regarding the sqlparse package, which reportedly fails to properly escape backslashes when generating Python and PHP code snippets from SQL input. This vulnerability could allow SQL injection attacks, potentially leading to the execution of attacker-controlled code in downstream environments.
What happened
The sqlparse package, available on PyPI, is under investigation for a high-severity vulnerability. The package generates Python and PHP code snippets from SQL input but does not properly escape backslashes. This oversight can lead to SQL injection, where an attacker could inject malicious SQL code. The vulnerability has not been exploited in the wild as of the latest reports.
Affected versions of sqlparse include all versions less than 0.5.4 and versions ranging from 0.1.0 to 0.6.0, with specific exclusions. Users of these versions are advised to take immediate action to mitigate potential risks.
What to do about it
- Avoid using the Python and PHP output modes of sqlparse until a fix is released.
- If using these modes, ensure that all SQL input is sanitized and trusted.
- Monitor the primary sources for updates on a potential fix.
- Consult the primary sources for the most current list of affected versions and any available patches.
How 0Day would have caught this
sqlparse is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.
Frequently asked questions
Am I affected?
You may be affected if you are using sqlparse versions less than 0.5.4 or any version between 0.1.0 and 0.6.0, with specific exclusions. Check the primary sources for the exact version ranges.
What should I do right now?
Avoid using the Python and PHP output modes of sqlparse. If you must use these modes, ensure all SQL input is sanitized and trusted. Monitor the primary sources for updates on a potential fix.
Is there a patch available?
No official fix has been published yet. Monitor the primary sources for updates.