sqlparse: formatting list of tuples leads to denial of service
Moderate severity
GitHub Reviewed
Published
Nov 25, 2025
in
andialbrecht/sqlparse
•
Updated Feb 13, 2026
Description
Published to the GitHub Advisory Database
Feb 13, 2026
Reviewed
Feb 13, 2026
Last updated
Feb 13, 2026
Summary
The below gist hangs while attempting to format a long list of tuples.
This was found while drafting a regression test for Dja
ngo 5.2's composite primary key feature, which allows querying composite fields with tuples.
References