CVE-2024-4340

Aliases:GHSA-2m57-hf25-phggPYSEC-2026-1940RHSA-2024:9984RHSA-2024:9986DEBIAN-CVE-2024-4340CGA-gfgr-vr95-32hhCGA-h998-2q4h-8w3hCGA-p9j8-39h4-w7p6
Advisory lineage Upstream: 0 Downstream: 12
Deferred
Published: 30 Apr 2024, 14:23
Last modified:03 Nov 2025, 22:05

Vulnerability Summary

Overall Risk (default)
medium
31/100
CVSS Score
7.5 HIGH
v3.1 (cve.org)
EPSS Score
3.24% LOW
3% probability -13.80%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

30 Apr 2024, 14:23
Published
Vulnerability first disclosed
03 Nov 2025, 22:05
Last Modified
Vulnerability information updated

Description

Passing a heavily nested list to sqlparse.parse() leads to a Denial of Service due to RecursionError.

CVSS Metrics

  • v3.1HIGHScore: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS Trends

Current EPSS score: 3.24% Percentile: 88%

Techniques & Countermeasures

  • CWE-674Uncontrolled Recursion

    The product does not properly control the amount of recursion that takes place, consuming excessive resources, such as allocated memory or the program stack.

Affected Systems

  • chainguardkubeflow-pipelines-visualization-server

    < 2.2.0-r0

  • chainguardpy3-sqlparse

    < 0.5.0-r0

  • wolfikubeflow-pipelines-visualization-server

    < 2.2.0-r0

  • wolfipy3-sqlparse

    < 0.5.0-r0

  • debiansqlparse

    < 0.4.1-1+deb11u1 | < 0.4.2-1+deb12u1 | < 0.5.0-1 | < 0.5.0-1

  • PyPIsqlparse

    < 0.5.0

  • redhatpython-sqlparse

    < 0:0.4.1-2.el9ost | < 0:0.4.1-2.el8ost

  • redhatpython3-sqlparse

    < 0:0.4.1-2.el9ost | < 0:0.4.1-2.el8ost

References (20)