PYPI · AUGUST 2026 · EARLY WARNING

sqlparse Package Vulnerability: SQL Injection Risk via Unescaped Backslashes

EARLY WARNING · UNCONFIRMED. This page describes a developing threat that 0Day surfaced from early signals and has not yet independently confirmed. Details may change. Always verify against the primary sources before acting.
Severity
HIGH
Affected component
sqlparse (pypi)
Affected versions
< 0.5.4 or >= 0.1.0, <= 0.1.0 or >= 0.1.1, <= 0.1.1 or >= 0.1.10, <= 0.1.10 or >= 0.1.11, <= 0.1.11 or >= 0.1.12, <= 0.1.12 or >= 0.1.13, <= 0.1.13 or >= 0.1.14, <= 0.1.14 or >= 0.1.15, <= 0.1.15 or >= 0.1.16, <= 0.1.16 or >= 0.1.17, <= 0.1.17 or >= 0.1.18, <= 0.1.18 or >= 0.1.19, <= 0.1.19 or >= 0.1.2, <= 0.1.2 or >= 0.1.3, <= 0.1.3 or >= 0.1.4, <= 0.1.4 or >= 0.1.5, <= 0.1.5 or >= 0.1.6, <= 0.1.6 or >= 0.1.7, <= 0.1.7 or >= 0.1.8, <= 0.1.8 or >= 0.1.9, <= 0.1.9 or >= 0.2.0, <= 0.2.0 or >= 0.2.1, <= 0.2.1 or >= 0.2.2, <= 0.2.2 or >= 0.2.3, <= 0.2.3 or >= 0.2.4, <= 0.2.4 or >= 0.3.0, <= 0.3.0 or >= 0.3.1, <= 0.3.1 or >= 0.4.0, <= 0.4.0 or >= 0.4.1, <= 0.4.1 or >= 0.4.2, <= 0.4.2 or >= 0.4.3, <= 0.4.3 or >= 0.4.4, <= 0.4.4 or >= 0.5.0, <= 0.5.0 or >= 0.5.1, <= 0.5.1 or >= 0.5.2, <= 0.5.2 or >= 0.5.3, <= 0.5.3 or < 0.5.0 or >= 0.1.0, <= 0.1.0 or >= 0.1.1, <= 0.1.1 or >= 0.1.10, <= 0.1.10 or >= 0.1.11, <= 0.1.11 or >= 0.1.12, <= 0.1.12 or >= 0.1.13, <= 0.1.13 or >= 0.1.14, <= 0.1.14 or >= 0.1.15, <= 0.1.15 or >= 0.1.16, <= 0.1.16 or >= 0.1.17, <= 0.1.17 or >= 0.1.18, <= 0.1.18 or >= 0.1.19, <= 0.1.19 or >= 0.1.2, <= 0.1.2 or >= 0.1.3, <= 0.1.3 or >= 0.1.4, <= 0.1.4 or >= 0.1.5, <= 0.1.5 or >= 0.1.6, <= 0.1.6 or >= 0.1.7, <= 0.1.7 or >= 0.1.8, <= 0.1.8 or >= 0.1.9, <= 0.1.9 or >= 0.2.0, <= 0.2.0 or >= 0.2.1, <= 0.2.1 or >= 0.2.2, <= 0.2.2 or >= 0.2.3, <= 0.2.3 or >= 0.2.4, <= 0.2.4 or >= 0.3.0, <= 0.3.0 or >= 0.3.1, <= 0.3.1 or >= 0.4.0, <= 0.4.0 or >= 0.4.1, <= 0.4.1 or >= 0.4.2, <= 0.4.2 or >= 0.4.3, <= 0.4.3 or >= 0.4.4, <= 0.4.4 or < 0.6.0 or >= 0.1.0, <= 0.1.0 or >= 0.1.1, <= 0.1.1 or >= 0.1.10, <= 0.1.10 or >= 0.1.11, <= 0.1.11 or >= 0.1.12, <= 0.1.12 or >= 0.1.13, <= 0.1.13 or >= 0.1.14, <= 0.1.14 or >= 0.1.15, <= 0.1.15 or >= 0.1.16, <= 0.1.16 or >= 0.1.17, <= 0.1.17 or >= 0.1.18, <= 0.1.18 or >= 0.1.19, <= 0.1.19 or >= 0.1.2, <= 0.1.2 or >= 0.1.3, <= 0.1.3 or >= 0.1.4, <= 0.1.4 or >= 0.1.5, <= 0.1.5 or >= 0.1.6, <= 0.1.6 or >= 0.1.7, <= 0.1.7 or >= 0.1.8, <= 0.1.8 or >= 0.1.9, <= 0.1.9 or >= 0.2.0, <= 0.2.0 or >= 0.2.1, <= 0.2.1 or >= 0.2.2, <= 0.2.2 or >= 0.2.3, <= 0.2.3 or >= 0.2.4, <= 0.2.4 or >= 0.3.0, <= 0.3.0 or >= 0.3.1, <= 0.3.1 or >= 0.4.0, <= 0.4.0 or >= 0.4.1, <= 0.4.1 or >= 0.4.2, <= 0.4.2 or >= 0.4.3, <= 0.4.3 or >= 0.4.4, <= 0.4.4 or >= 0.5.0, <= 0.5.0 or >= 0.5.1, <= 0.5.1 or >= 0.5.2, <= 0.5.2 or >= 0.5.3, <= 0.5.3 or >= 0.5.4, <= 0.5.4 or >= 0.5.5, <= 0.5.5 or < 0.6.0 or >= 0.1.0, <= 0.1.0 or >= 0.1.1, <= 0.1.1 or >= 0.1.10, <= 0.1.10 or >= 0.1.11, <= 0.1.11 or >= 0.1.12, <= 0.1.12 or >= 0.1.13, <= 0.1.13 or >= 0.1.14, <= 0.1.14 or >= 0.1.15, <= 0.1.15 or >= 0.1.16, <= 0.1.16 or >= 0.1.17, <= 0.1.17 or >= 0.1.18, <= 0.1.18 or >= 0.1.19, <= 0.1.19 or >= 0.1.2, <= 0.1.2 or >= 0.1.3, <= 0.1.3 or >= 0.1.4, <= 0.1.4 or >= 0.1.5, <= 0.1.5 or >= 0.1.6, <= 0.1.6 or >= 0.1.7, <= 0.1.7 or >= 0.1.8, <= 0.1.8 or >= 0.1.9, <= 0.1.9 or >= 0.2.0, <= 0.2.0 or >= 0.2.1, <= 0.2.1 or >= 0.2.2, <= 0.2.2 or >= 0.2.3, <= 0.2.3 or >= 0.2.4, <= 0.2.4 or >= 0.3.0, <= 0.3.0 or >= 0.3.1, <= 0.3.1 or >= 0.4.0, <= 0.4.0 or >= 0.4.1, <= 0.4.1 or >= 0.4.2, <= 0.4.2 or >= 0.4.3, <= 0.4.3 or >= 0.4.4, <= 0.4.4 or >= 0.5.0, <= 0.5.0 or >= 0.5.1, <= 0.5.1 or >= 0.5.2, <= 0.5.2 or >= 0.5.3, <= 0.5.3 or >= 0.5.4, <= 0.5.4 or >= 0.5.5, <= 0.5.5 or >= 0.4.0, < 0.4.2 or >= 0.4.0, <= 0.4.0 or >= 0.4.1, <= 0.4.1 or >= 0.1.15, < 0.4.4 or >= 0.1.15, <= 0.1.15 or >= 0.1.16, <= 0.1.16 or >= 0.1.17, <= 0.1.17 or >= 0.1.18, <= 0.1.18 or >= 0.1.19, <= 0.1.19 or >= 0.2.0, <= 0.2.0 or >= 0.2.1, <= 0.2.1 or >= 0.2.2, <= 0.2.2 or >= 0.2.3, <= 0.2.3 or >= 0.2.4, <= 0.2.4 or >= 0.3.0, <= 0.3.0 or >= 0.3.1, <= 0.3.1 or >= 0.4.0, <= 0.4.0 or >= 0.4.1, <= 0.4.1 or >= 0.4.2, <= 0.4.2 or >= 0.4.3, <= 0.4.3 or >= 0.4.0, < 0.4.2 or >= 0.4.0, <= 0.4.0 or >= 0.4.1, <= 0.4.1 or >= 0.1.15, < 0.4.4 or >= 0.1.15, <= 0.1.15 or >= 0.1.16, <= 0.1.16 or >= 0.1.17, <= 0.1.17 or >= 0.1.18, <= 0.1.18 or >= 0.1.19, <= 0.1.19 or >= 0.2.0, <= 0.2.0 or >= 0.2.1, <= 0.2.1 or >= 0.2.2, <= 0.2.2 or >= 0.2.3, <= 0.2.3 or >= 0.2.4, <= 0.2.4 or >= 0.3.0, <= 0.3.0 or >= 0.3.1, <= 0.3.1 or >= 0.4.0, <= 0.4.0 or >= 0.4.1, <= 0.4.1 or >= 0.4.2, <= 0.4.2 or >= 0.4.3, <= 0.4.3 or < 0.5.0 or >= 0.1.0, <= 0.1.0 or >= 0.1.1, <= 0.1.1 or >= 0.1.10, <= 0.1.10 or >= 0.1.11, <= 0.1.11 or >= 0.1.12, <= 0.1.12 or >= 0.1.13, <= 0.1.13 or >= 0.1.14, <= 0.1.14 or >= 0.1.15, <= 0.1.15 or >= 0.1.16, <= 0.1.16 or >= 0.1.17, <= 0.1.17 or >= 0.1.18, <= 0.1.18 or >= 0.1.19, <= 0.1.19 or >= 0.1.2, <= 0.1.2 or >= 0.1.3, <= 0.1.3 or >= 0.1.4, <= 0.1.4 or >= 0.1.5, <= 0.1.5 or >= 0.1.6, <= 0.1.6 or >= 0.1.7, <= 0.1.7 or >= 0.1.8, <= 0.1.8 or >= 0.1.9, <= 0.1.9 or >= 0.2.0, <= 0.2.0 or >= 0.2.1, <= 0.2.1 or >= 0.2.2, <= 0.2.2 or >= 0.2.3, <= 0.2.3 or >= 0.2.4, <= 0.2.4 or >= 0.3.0, <= 0.3.0 or >= 0.3.1, <= 0.3.1 or >= 0.4.0, <= 0.4.0 or >= 0.4.1, <= 0.4.1 or >= 0.4.2, <= 0.4.2 or >= 0.4.3, <= 0.4.3 or >= 0.4.4, <= 0.4.4
Patched version
Not yet available
GHSA-3496-9G83-7V6X

An early warning has been issued regarding the sqlparse package, which reportedly fails to properly escape backslashes when generating Python and PHP code snippets from SQL input. This vulnerability could allow SQL injection attacks, potentially leading to the execution of attacker-controlled code in downstream environments.

What happened

The sqlparse package, available on PyPI, is under investigation for a high-severity vulnerability. The package generates Python and PHP code snippets from SQL input but does not properly escape backslashes. This oversight can lead to SQL injection, where an attacker could inject malicious SQL code. The vulnerability has not been exploited in the wild as of the latest reports.

Affected versions of sqlparse include all versions less than 0.5.4 and versions ranging from 0.1.0 to 0.6.0, with specific exclusions. Users of these versions are advised to take immediate action to mitigate potential risks.

What to do about it

How 0Day would have caught this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If sqlparse is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Frequently asked questions

Am I affected?

You may be affected if you are using sqlparse versions less than 0.5.4 or any version between 0.1.0 and 0.6.0, with specific exclusions. Check the primary sources for the exact version ranges.

What should I do right now?

Avoid using the Python and PHP output modes of sqlparse. If you must use these modes, ensure all SQL input is sanitized and trusted. Monitor the primary sources for updates on a potential fix.

Is there a patch available?

No official fix has been published yet. Monitor the primary sources for updates.

Sources

Join the 0Day waitlist →

← Back to all threats